CVE-2026-48497
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is strictly less than 255 octets, contradicting DNS specification rfc1035#section-2.3.4 that the name can be 255 or less octets. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-480
- Published
- 2026-06-26
- Last modified
- 2026-06-26
Affected products
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
Weakness type
Related vulnerabilities
- CVE-2026-79643 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-63421 — Keystone: `graphql.maxTake` bypass with negative `take`
- CVE-2026-44722 — pyzipper: Encryption bypass for small files encrypted with pyzipper
- CVE-2026-15043 — DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
- CVE-2026-4748 — pf silently ignores certain rules
- CVE-2025-52985 — Junos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 entries it's not matching
- CVE-2024-35190 — Asterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests
- CVE-2022-1947 — Use of Incorrect Operator in polonel/trudesk