Vulnerability Description
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted ProcessingResponse messages. This can occur when the first response in the batch causes the gRPC stream object to be destroyed, leading to a use-after-free error when Envoy attempts to process subsequent responses in the same gRPC message. This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Envoyproxy | Envoy | >= 1.34.0, < 1.35.13 |
Related Weaknesses (CWE)
References
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-68cv-hq5f-g6xvExploitVendor Advisory
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-68cv-hq5f-g6xvExploitVendor Advisory
FAQ
What is CVE-2026-47207?
CVE-2026-47207 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC me...
How severe is CVE-2026-47207?
CVE-2026-47207 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-47207?
Check the references section above for vendor advisories and patch information. Affected products include: Envoyproxy Envoy.