GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: stale RequestDecoder pointer after HTTP/3 stream recreation crashes the proxy

CVSS 7.5CVE-2026-73512Container, Kubernetes & orchestrationcurated

Impact

HttpDatagramHandler caches the current RequestDecoder when the Capsule Protocol is enabled. Stream recreation - an internal redirect, for instance - replaces the ActiveStream without updating that cached pointer, so a following HTTP/3 datagram dispatches through a freed decoder and the process dies. An unauthenticated client can therefore drop an Envoy instance at will, taking out every connection it was carrying. On a GPU fleet that fronts inference endpoints or mesh traffic through Envoy, repeated crashes mean sustained denial of service on in-flight requests; only deployments with HTTP/3 datagrams plus Capsule Protocol enabled and a stream-recreation path configured are reachable.

Who can reach it

Any unauthenticated client that can open an HTTP/3 connection to a listener with datagrams and Capsule Protocol enabled, where the request hits a stream-recreation path such as an internal redirect.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4 or 1.39.1 and restart the proxy; rolling restart, no node drain. If patching has to wait, disable HTTP/3 datagram / Capsule Protocol support or the internal-redirect policy on the affected routes.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.