VDB
CVE-2026-73549
CVE-2026-73549
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters
EPSS 0.62% · 48.0th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.62%
48.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | envoy | |
| Bitnami | envoy | 0, 1.37.0, 1.38.0 |
Timeline
- Aug 26, 2026 CVE Published
- Sep 22, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 5, 2026 CVE Updated
- Oct 6, 2026 EPSS Score
- Oct 8, 2026 EPSS Score
References
- https://github.com/envoyproxy/envoy/commit/109e5a5b08ad10d99074cefd55a747a16ee64da7 url
- https://github.com/envoyproxy/envoy/commit/59b1744a6cb62746db418ac06fc5e359fd25fdb7 url
- https://github.com/envoyproxy/envoy/commit/6e39f4c94deff7a60d382c2d95883e0ea49ff691 url
- https://github.com/envoyproxy/envoy/commit/ab2dca2d65b079768230a7c3d825afeefa330215 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.36.10 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.37.6 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.38.4 url
- https://github.com/envoyproxy/envoy/releases/tag/v1.39.1 url
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-jp5f-qr64-c9vw url
- https://nvd.nist.gov/vuln/detail/CVE-2026-73549 url