Database/Container, Kubernetes & orchestration
Envoy: malformed upstream response trailers dispatch through a freed decoder and crash the proxy
Impact
An upstream that sends a trailer HEADERS frame without END_STREAM makes Envoy complete and deferred-delete the ActiveRequest while oghttp2 keeps the stream open, leaving a dangling response_decoder_. A later frame on that stream dispatches through freed memory and takes the process down. Where Envoy is the ingress or mesh sidecar in front of inference endpoints, that is a loss of the serving path - a sidecar crashloop drops every request for the pod, and an edge proxy crash drops the whole tenant-facing front door. Only the optional oghttp2 codec is affected; the default nghttp2 codec rejects the malformed trailers, and the trigger is upstream-side only.
Who can reach it
Whoever controls or can impersonate an upstream host that Envoy proxies to, with oghttp2 explicitly enabled for upstream HTTP/2. Not reachable from a plain downstream client on a default build.
What to do
Upgrade to Envoy 1.36.10, 1.37.6, 1.38.4 or 1.39.1. If you cannot patch now, switch the upstream HTTP/2 codec back to the default nghttp2, which rejects these trailers. Rolling restart of the proxy fleet or sidecar redeploy; no node maintenance.
References
Related entries
- Envoy: duplicate Host headers escape request header limits and let a client OOM-kill the proxyCVE-2026-73550 · Envoy (HTTP/2 duplicate Host header handling, header-limit accounting)High
- Skipper: OPA body policies authorize oversized requests because truncated_body is derived from Content-LengthCVE-2026-86043 · Skipper HTTP router (opaAuthorizeRequestWithBody / OPA body truncation)High
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessCVE-2022-21953 · RancherHigh
- CRI-O: restored checkpoints re-apply archive mounts, bypassing pod-spec host mount validationCVE-2024-8676 · CRI-O (container checkpoint/restore endpoint)High
- Podman: files written to bind mounts during build persist in the host build context directoryCVE-2025-4953 · Podman (podman build, RUN --mount=type=bind)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.