CVE-2026-48497: CWE-480: Use of Incorrect Operator in envoyproxy envoy
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is strictly less than 255 octets, contradicting DNS specification rfc1035#section-2.3.4 that the name can be 255 or less octets. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
AI Analysis
Technical Summary
Envoy proxy has a vulnerability (CWE-480) in its UDP DNS filter where queries with DNS names of length 255 octets cause abnormal process termination. This is due to an incorrect operator enforcing a runtime precondition that the query name length must be less than 255 octets, violating RFC 1035 which allows names up to 255 octets. This flaw can cause a denial of service by crashing the process. The vulnerability affects versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1 and has been fixed in these versions.
Potential Impact
The vulnerability results in a denial of service condition by causing the Envoy process to terminate abnormally when handling DNS queries with names of 255 octets. There is no impact on confidentiality or integrity. The CVSS score is 5.9 (medium severity) reflecting network attack vector, high attack complexity, no privileges required, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade to Envoy versions 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later where this vulnerability is fixed. No other mitigation is indicated or required.
CVE-2026-48497: CWE-480: Use of Incorrect Operator in envoyproxy envoy
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is strictly less than 255 octets, contradicting DNS specification rfc1035#section-2.3.4 that the name can be 255 or less octets. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
CVSS v3.1
Score 5.9medium
Affected software
pkg:github/envoyproxy/envoyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Envoy proxy has a vulnerability (CWE-480) in its UDP DNS filter where queries with DNS names of length 255 octets cause abnormal process termination. This is due to an incorrect operator enforcing a runtime precondition that the query name length must be less than 255 octets, violating RFC 1035 which allows names up to 255 octets. This flaw can cause a denial of service by crashing the process. The vulnerability affects versions prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1 and has been fixed in these versions.
Potential Impact
The vulnerability results in a denial of service condition by causing the Envoy process to terminate abnormally when handling DNS queries with names of 255 octets. There is no impact on confidentiality or integrity. The CVSS score is 5.9 (medium severity) reflecting network attack vector, high attack complexity, no privileges required, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade to Envoy versions 1.35.11, 1.36.7, 1.37.3, or 1.38.1 or later where this vulnerability is fixed. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-21T15:33:08.292Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3ec10ed9e07477746fae28
Added to database: 06/26/2026, 18:12:30 UTC
Last enriched: 06/26/2026, 18:22:49 UTC
Last updated: 08/08/2026, 12:41:11 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.