CVE-2026-73548
Received
Received - Intake
HTTP/2 Request Smuggling in Envoy Proxy
Vulnerability report for CVE-2026-73548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-21
Last updated on: 2026-09-21
Assigner: GitHub, Inc.
Description
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthenticated HTTP/2 client can place a complete HTTP/1.1 request in extended CONNECT data; Envoy downgrades the request, writes the data unframed to a keep-alive HTTP/1.1 upstream, and returns the socket to the shared pool while the smuggled response remains queued. A different downstream client can then receive the attacker's response. The relevant scope boundary is that webSocket upgrades, plain CONNECT, disabled backend keep-alive, per-downstream pools, and max_requests_per_connection set to 1 are not affected by the demonstrated path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| envoy | envoy | 1.36.10 |
| envoy | envoy | 1.37.6 |
| envoy | envoy | 1.38.4 |
| envoy | envoy | 1.39.1 |
| envoy | envoy | to 1.36.10 (exc) |
| envoy | envoy | to 1.37.6 (exc) |
| envoy | envoy | to 1.38.4 (exc) |
| envoy | envoy | to 1.39.1 (exc) |
| envoyproxy | envoy | 1.36.10 |
| envoyproxy | envoy | 1.37.6 |
| envoyproxy | envoy | 1.38.4 |
| envoyproxy | envoy | 1.39.1 |
| envoyproxy | envoy | to 1.40.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-444 | The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination. |