VDB
CVE-2026-48521
CVE-2026-48521
PUBLISHED
CVSS 5.900000095367432 MEDIUM
Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null
EPSS 0.74% · 53.1th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.74%
53.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | envoy | |
| Bitnami | envoy | 0, 1.37.0, 1.38.0 |
Timeline
- Aug 26, 2026 CVE Published
- Sep 19, 2026 CVE Updated
- Sep 22, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
References
- https://github.com/envoyproxy/envoy/commit/8ef2da8527fcd17388b046c1add4fb47fb5d0868 url
- https://github.com/envoyproxy/envoy/commit/cec4899acf03cf551f28611a5f32385648d95f96 url
- https://github.com/envoyproxy/envoy/commit/e7b4839beef7f43594ce8e94c4563c80db04a8a7 url
- https://github.com/envoyproxy/envoy/commit/f5436f44103fb14cb8ba42a8db0f54a06c98c45a url
- https://github.com/envoyproxy/envoy/releases/tag/v1.36.10 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.37.6 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.38.4 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.39.1 url
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-5vff-j9p4-38j3 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-48521 url