CVE Explorer
CVE-2026-26330
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the response phase limit request fails directly, it may crash Envoy. When both the request phase limit and response phase limit are enabled, the safe gRPC client instance will be re-used for both the request phase request and response phase request. But after the request
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"envoy","vendor":"envoyproxy","versions":[{"status":"affected","version":">= 1.37.0, < 1.37.1"},{"status":"affected","version":">= 1.36.0, < 1.36.5"},{"status":"affected","version":">= 1.35.0, < 1.35.9"},{"status":"affected","version":"< 1.34.13"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b7635a8a5260af521eddc721edeeb06eeda0d254752b52d396e5de5ab72fcbfd · sha256:aa6c141c0af6f80b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b7635a8a5260af521eddc721edeeb06eeda0d254752b52d396e5de5ab72fcbfd · sha256:aa6c141c0af6f80b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b7635a8a5260af521eddc721edeeb06eeda0d254752b52d396e5de5ab72fcbfd · sha256:aa6c141c0af6f80b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-c23c-rp3m-vpg3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-c23c-rp3m-vpg3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b7635a8a5260af521eddc721edeeb06eeda0d254752b52d396e5de5ab72fcbfd · sha256:aa6c141c0af6f80b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.