CVE Explorer
CVE-2026-48497
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is str
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"envoy","vendor":"envoyproxy","versions":[{"status":"affected","version":">= 1.38.0, < 1.38.1"},{"status":"affected","version":">= 1.37.0, < 1.37.3"},{"status":"affected","version":">= 1.36.0, < 1.36.7"},{"status":"affected","version":"< 1.35.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:84b13cfc6e755bb002bc8f4e8e9aba4eff18f8b1fd595231cd9fb4d4eae11286 · sha256:055009b4af773d5a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:84b13cfc6e755bb002bc8f4e8e9aba4eff18f8b1fd595231cd9fb4d4eae11286 · sha256:055009b4af773d5a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-480","description":"CWE-480: Use of Incorrect Operator","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:84b13cfc6e755bb002bc8f4e8e9aba4eff18f8b1fd595231cd9fb4d4eae11286 · sha256:055009b4af773d5a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-j6g2-wf95-q66q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-j6g2-wf95-q66q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:84b13cfc6e755bb002bc8f4e8e9aba4eff18f8b1fd595231cd9fb4d4eae11286 · sha256:055009b4af773d5a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.