GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: scoped IPv6 address reconstruction aborts the proxy process in ORIGINAL_DST and QUIC paths

CVSS 5.3CVE-2026-73549Container, Kubernetes & orchestrationcurated

Impact

Envoy reconstructs scoped IPv6 addresses through addressAsString and Ipv6Instance; the resulting string carries a percent scope identifier that inet_pton cannot parse, raising an exception or aborting. A kernel-provided scoped IPv6 original destination in an ORIGINAL_DST transparent-proxy deployment, or traffic on the affected QUIC client-address path, therefore terminates the proxy process. Where Envoy is the ingress or the mesh data plane, that drops every connection through that instance; a client able to reproduce the condition can keep crash-looping the proxy, which cuts off service traffic without touching the workloads themselves.

Who can reach it

A client reaching an Envoy listener in a transparent-proxy (ORIGINAL_DST) deployment with scoped IPv6 destinations, or over the affected QUIC path. CVSS marks low privilege and high attack complexity. The HTTP use_http_header override is not a path here - it rejects scoped addresses earlier.

What to do

Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 and restart the proxies - a rolling restart of sidecars or ingress pods, no node-level maintenance. Until then, deployments not using IPv6 transparent proxying or QUIC are not exposed; disabling QUIC listeners removes that half of the surface.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.