GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: null-pointer dereference selecting an HTTP/3 connection pool crashes a worker

CVSS 5.9CVE-2026-48521Container, Kubernetes & orchestrationcurated

Impact

ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while choosing an HTTP/3 connection pool without a null check. The LoadBalancerContext implementations used by synthetic requests, request mirroring, health checks and async-client calls can legitimately supply no transport-socket options, so with auto_config and HTTP/3 in the protocol set, routine traffic - including Envoy's own health checks - crashes a worker. For an operator this is a self-inflicted outage risk on any mesh or gateway that has turned on HTTP/3 auto-config: the trigger is normal operation rather than an attacker, and health-check paths make it recurrent. Availability only.

Who can reach it

No attacker is strictly required: traffic reaching one of those contexts on an Envoy with HTTP/3 enabled via auto_config is enough, which includes internally generated health-check and mirror requests. CVSS records AV:N/AC:H/PR:N.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 for your branch and roll the proxies - a rolling restart of gateways and sidecars, no node maintenance. Immediate mitigation is to remove HTTP/3 from the protocol set or disable auto_config on affected clusters, which avoids the vulnerable branch entirely.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.