CVE-2026-48042
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.56%
- CWE
- CWE-1124
- Published
- 2026-06-26
- Last modified
- 2026-06-26
Affected products
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
Weakness type
Related vulnerabilities
- CVE-2026-55620 — eml_parser: DoS via deeply nested parens in Received headers
- CVE-2026-55619 — eml_parser: Parser DoS via deeply nested parentheses in e-mail headers