{"id":"CVE-2026-73548","published":"2026-09-21T20:17:28.397","lastModified":"2026-09-21T20:17:28.397","description":"Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthenticated HTTP/2 client can place a complete HTTP/1.1 request in extended CONNECT data; Envoy downgrades the request, writes the data unframed to a keep-alive HTTP/1.1 upstream, and returns the socket to the shared pool while the smuggled response remains queued. A different downstream client can then receive the attacker's response. The relevant scope boundary is that webSocket upgrades, plain CONNECT, disabled backend keep-alive, per-downstream pools, and max_requests_per_connection set to 1 are not affected by the demonstrated path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-444"],"vendors":[],"products":[],"references":[{"url":"https://github.com/envoyproxy/envoy/commit/309855626966cff176155c821043ed3b44671361","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/3c7998545a9c9fb3933a4bc1907d92f0e752bc2b","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/4633b8cce3d15b8734eefe232e30c12b0140b91c","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/bd6711f2617658e28dfa3df3dace6bfe3cfc0766","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.36.10","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.37.6","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.38.4","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.39.1","tags":[]},{"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-3vhp-c83q-jqc2","tags":[]}],"exploitRefs":[{"url":"https://github.com/envoyproxy/envoy/commit/309855626966cff176155c821043ed3b44671361","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/3c7998545a9c9fb3933a4bc1907d92f0e752bc2b","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/4633b8cce3d15b8734eefe232e30c12b0140b91c","tags":[]},{"url":"https://github.com/envoyproxy/envoy/commit/bd6711f2617658e28dfa3df3dace6bfe3cfc0766","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.36.10","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.37.6","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.38.4","tags":[]},{"url":"https://github.com/envoyproxy/envoy/releases/tag/v1.39.1","tags":[]},{"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-3vhp-c83q-jqc2","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an unauthenticated HTTP/2 client to smuggle a complete HTTP/1.1 request and response through Envoy, potentially intercepting sensitive data. This matters because it can lead to unauthorized access and data exposure.","exploitability":"Exploitation requires an attacker to send a specific HTTP/2 request with CONNECT data; preconditions include the target running an affected version of Envoy without proper configuration to mitigate this issue.","blast_radius":"If exploited, this could result in significant data breaches and unauthorized access across multiple downstream clients sharing the same connection pool.","remediation":"Upgrade to Envoy versions 1.36.10, 1.37.6, 1.38.4, or 1.39.1 immediately to mitigate this vulnerability.","tags":["http","proxy","smuggling","upgrade","patch"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:13:23.484Z"}}