Database/Container, Kubernetes & orchestration
Envoy: null-pointer dereference selecting an HTTP/3 connection pool crashes a worker
Impact
ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while choosing an HTTP/3 connection pool without a null check. The LoadBalancerContext implementations used by synthetic requests, request mirroring, health checks and async-client calls can legitimately supply no transport-socket options, so with auto_config and HTTP/3 in the protocol set, routine traffic - including Envoy's own health checks - crashes a worker. For an operator this is a self-inflicted outage risk on any mesh or gateway that has turned on HTTP/3 auto-config: the trigger is normal operation rather than an attacker, and health-check paths make it recurrent. Availability only.
Who can reach it
No attacker is strictly required: traffic reaching one of those contexts on an Envoy with HTTP/3 enabled via auto_config is enough, which includes internally generated health-check and mirror requests. CVSS records AV:N/AC:H/PR:N.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 for your branch and roll the proxies - a rolling restart of gateways and sidecars, no node maintenance. Immediate mitigation is to remove HTTP/3 from the protocol set or disable auto_config on affected clusters, which avoids the vulnerable branch entirely.
References
Related entries
- Envoy: use-after-free in the HTTP ext_authz client crashes workers under production trafficCVE-2026-50572 · Envoy HTTP ext_authz client (RawHttpClientImpl stale callback)Medium
- KEDA PostgreSQL scaler: connection-string injection redirects the DB connection and leaks credentialsCVE-2026-53572 · KEDA PostgreSQL scaler (escapePostgreConnectionParameter connection-string escaping)Medium
- Cilium: A namespaced HTTPRoute can mirror another tenant's HTTP trafficCVE-2026-56742 · CiliumMedium
- etcd gateway (--discovery-srv secure endpoint validation): TLS VALIDATION THAT VALIDATES NOTHING: the etcd gateway'sNCVD-2020-007-etcd-gateway-discovery-srv-secur · etcd gateway (--discovery-srv secure endpoint validation)Medium
- etcd: No password length validation permits one-character etcd passwordsCVE-2020-15115 · etcdMedium
- Kubernetes (kube-proxy): Windows kube-proxy forwards LoadBalancer traffic to local processes on the same portCVE-2021-25736 · Kubernetes (kube-proxy)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.