Database/Container, Kubernetes & orchestration
Envoy: scoped IPv6 address reconstruction aborts the proxy process in ORIGINAL_DST and QUIC paths
Impact
Envoy reconstructs scoped IPv6 addresses through addressAsString and Ipv6Instance; the resulting string carries a percent scope identifier that inet_pton cannot parse, raising an exception or aborting. A kernel-provided scoped IPv6 original destination in an ORIGINAL_DST transparent-proxy deployment, or traffic on the affected QUIC client-address path, therefore terminates the proxy process. Where Envoy is the ingress or the mesh data plane, that drops every connection through that instance; a client able to reproduce the condition can keep crash-looping the proxy, which cuts off service traffic without touching the workloads themselves.
Who can reach it
A client reaching an Envoy listener in a transparent-proxy (ORIGINAL_DST) deployment with scoped IPv6 destinations, or over the affected QUIC path. CVSS marks low privilege and high attack complexity. The HTTP use_http_header override is not a path here - it rejects scoped addresses earlier.
What to do
Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 and restart the proxies - a rolling restart of sidecars or ingress pods, no node-level maintenance. Until then, deployments not using IPv6 transparent proxying or QUIC are not exposed; disabling QUIC listeners removes that half of the surface.
References
Related entries
- Envoy: path normalization misses ..;param segments, bypassing path-based routing and RBACCVE-2026-73551 · Envoy (URL path normalization, dot segments with semicolon parameters)Medium
- Rancher Fleet: Helm template preprocessing reaches the network, leaking cluster metadata via DNSCVE-2026-75036 · Rancher Fleet controller (Helm template preprocessing / GitRepo bundle content)Medium
- containerd: containerd-shim abstract-socket API exposed to host-network containersCVE-2020-15257 · containerdMedium
- Kubernetes (kube-apiserver): Aggregated API server can redirect apiserver clientsCVE-2022-3172 · Kubernetes (kube-apiserver)Medium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
- Contrast: untrusted host can write arbitrary files into a confidential container via an unbacked VOLUME pathCVE-2025-71424 · Edgeless Systems Contrast (confidential-containers runtime, OCI VOLUME mount handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.