Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48042

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

A flaw was found in Envoy, an open-source edge and service proxy. A remote attacker could exploit this vulnerability by sending deeply nested JSON objects to the affected system. This could lead to a stack overflow during the destruction of JSON objects, resulting in a Denial of Service (DoS) for the Envoy proxy.

Отчет

This is an Important denial of service flaw in Envoy, an open-source edge and service proxy. A remote attacker can trigger a stack overflow by sending deeply nested JSON objects, leading to service unavailability. This vulnerability affects systems where Envoy is deployed and exposed to untrusted input, potentially disrupting critical proxy functionalities.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Will not fix
OpenShift Service Mesh 3openshift-service-mesh/istio-proxyv2-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2494196envoy: Envoy: Denial of Service via deeply nested JSON objects

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

CVSS3: 7.5
debian
около 1 месяца назад

Envoy is an open source edge and service proxy designed for cloud-nati ...

7.5 High

CVSS3