{"id":"CVE-2026-50572","published":"2026-09-21T20:17:25.970","lastModified":"2026-09-21T20:17:25.970","description":"Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is rejected. When RawHttpClientImpl::onSuccess later processes the authorization response, it can invoke callbacks_ after the callback owner has been destroyed, causing a use-after-free and process crash under production traffic. The relevant scope boundary is that the vulnerable path uses the HTTP ext_authz client; the advisory does not establish the same trigger for unrelated filters. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.","cvssScore":5.9,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://github.com/envoyproxy/envoy/commit/8dacef38337aeffd62866b5c5910104b63b33db8","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/a49085623654e27e9ad6298928557644b849d7ce","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/c1b29534a294cb0999e99e1fe0de000310165f03","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/c524571ffad517ba650d9563f85afa89194e2cfb","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.36.10","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.37.6","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.38.4","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.39.1","tags":[]},{"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-q8wp-gf7q-m8cv","tags":[]}],"exploitRefs":[{"url":"https://github.com/envoyproxy/envoy/commit/8dacef38337aeffd62866b5c5910104b63b33db8","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/a49085623654e27e9ad6298928557644b849d7ce","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/c1b29534a294cb0999e99e1fe0de000310165f03","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/c524571ffad517ba650d9563f85afa89194e2cfb","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.36.10","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.37.6","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.38.4","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.39.1","tags":[]},{"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-q8wp-gf7q-m8cv","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a use-after-free condition in Envoy's HTTP external-authorization client, leading to potential process crashes under production traffic.","exploitability":"Exploitation requires specific conditions where requests are rejected and then processed later, making it moderately difficult but feasible with the right setup.","blast_radius":"If exploited, this could lead to service disruptions or crashes in affected Envoy deployments handling high traffic.","remediation":"Update to Envoy versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1 to mitigate the vulnerability.","tags":["use-after-free","crash","proxy","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:23:37.588Z"}}