GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: malformed upstream response trailers dispatch through a freed decoder and crash the proxy

CVSS 7.5CVE-2026-73513Container, Kubernetes & orchestrationcurated

Impact

An upstream that sends a trailer HEADERS frame without END_STREAM makes Envoy complete and deferred-delete the ActiveRequest while oghttp2 keeps the stream open, leaving a dangling response_decoder_. A later frame on that stream dispatches through freed memory and takes the process down. Where Envoy is the ingress or mesh sidecar in front of inference endpoints, that is a loss of the serving path - a sidecar crashloop drops every request for the pod, and an edge proxy crash drops the whole tenant-facing front door. Only the optional oghttp2 codec is affected; the default nghttp2 codec rejects the malformed trailers, and the trigger is upstream-side only.

Who can reach it

Whoever controls or can impersonate an upstream host that Envoy proxies to, with oghttp2 explicitly enabled for upstream HTTP/2. Not reachable from a plain downstream client on a default build.

What to do

Upgrade to Envoy 1.36.10, 1.37.6, 1.38.4 or 1.39.1. If you cannot patch now, switch the upstream HTTP/2 codec back to the default nghttp2, which rejects these trailers. Rolling restart of the proxy fleet or sidecar redeploy; no node maintenance.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.