Abnormal process termination in DNS UDP filter
Fixed in: Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2
details
- Finding IDs
- F-ENVOY-001-002
- CVE
- CVE-2026-48497
- GHSA
- GHSA-j6g2-wf95-q66q
- Status
- patched
- CWE
- CWE-480
- Fixed in
- Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2
- Recorded credit
- finder: @1seal
- Note
- GHSA-j6g2-wf95-q66q · abnormal process termination in the Envoy DNS UDP filter for a 255-octet DNS query name. maps to local F-ENVOY-001-002; affected versions are <1.39 and patched versions are 1.35.12, 1.36.8, 1.37.4, and 1.38.2.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Abnormal process termination in DNS UDP filter
- Upstream CWE
- CWE-480
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: finder (accepted)
F-ENVOY-001-002: Input / state handling. A valid 255-octet DNS name violates an incorrect runtime precondition. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ENVOY-001-002
Security area (1seal assessment): Availability. A valid 255-octet DNS name violates an incorrect runtime precondition. Reviewed 24 Sep 2026.