CVE-2026-50572 Overview
Envoy is an open source edge and service proxy for cloud-native applications. A use-after-free vulnerability affects Envoy's HTTP external authorization (ext_authz) client in versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1. The client can retain a stale request callback after a request is rejected. When RawHttpClientImpl::onSuccess later processes the authorization response, it invokes callbacks_ after the callback owner has been destroyed. This triggers a use-after-free [CWE-416] and process crash under production traffic. The issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.
Critical Impact
Remote attackers can crash Envoy proxy processes serving traffic through the HTTP ext_authz filter, causing service disruption for all clients routed through the affected proxy.
Affected Products
- Envoy versions prior to 1.36.10 (1.36.x branch)
- Envoy versions prior to 1.37.6 (1.37.x branch)
- Envoy versions prior to 1.38.4 (1.38.x branch) and prior to 1.39.1 (1.39.x branch)
Discovery Timeline
- 2026-09-21 - CVE-2026-50572 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-50572
Vulnerability Analysis
The vulnerability resides in Envoy's HTTP ext_authz client, which forwards authorization decisions to an external HTTP service. When Envoy rejects a request during authorization, the callback owner can be destroyed while an asynchronous authorization response is still in flight. When RawHttpClientImpl::onSuccess later fires, it dereferences the stale callbacks_ pointer, producing a use-after-free condition and a process crash.
The advisory scopes the trigger to the HTTP ext_authz client path. Unrelated filters are not confirmed to be affected. Because Envoy handles many concurrent connections in a single process, a crash affects all clients served by the worker.
Root Cause
The root cause is improper lifetime management of the callbacks_ pointer inside the ext_authz HTTP client. The client did not null out or safely capture the callback pointer before invoking it, so a rejection path could destroy the callback owner while the pointer remained resident in the client instance. A later successful HTTP response then invoked the freed callback.
Attack Vector
An attacker sends HTTP requests to an Envoy proxy configured with the HTTP ext_authz filter. By inducing request rejections while an authorization response is still being processed, the attacker races the callback lifecycle and triggers the use-after-free. Successful exploitation crashes the Envoy process, resulting in denial of service for all traffic on that worker. Confidentiality and integrity impact are not indicated by the advisory.
// Patch from source/extensions/filters/common/ext_authz/ext_authz_grpc_impl.cc
authz_response->dynamic_metadata = response->dynamic_metadata();
}
- callbacks_->onComplete(std::move(authz_response));
+ RequestCallbacks* callbacks = callbacks_;
callbacks_ = nullptr;
+ callbacks->onComplete(std::move(authz_response));
}
void GrpcClientImpl::onFailure(Grpc::Status::GrpcStatus status, const std::string&,
Source: Envoy Commit 8dacef3
The fix captures callbacks_ into a local variable, clears the member pointer, and only then invokes onComplete. This prevents re-entry through a stale pointer if the callback owner is destroyed during processing.
Detection Methods for CVE-2026-50572
Indicators of Compromise
- Unexpected Envoy worker process crashes or restarts under normal or elevated traffic
- Segmentation faults or ASAN heap-use-after-free reports in Envoy logs when the HTTP ext_authz filter is enabled
- Spikes in 5xx responses coinciding with ext_authz rejection events
Detection Strategies
- Correlate Envoy crash dumps and SIGSEGV events with concurrent ext_authz request denials in access logs
- Query the running Envoy version through the admin /server_info endpoint and flag builds older than 1.36.10, 1.37.6, 1.38.4, or 1.39.1
- Audit Envoy configurations for envoy.filters.http.ext_authz filters using the HTTP service transport rather than gRPC
Monitoring Recommendations
- Monitor the server.live and process restart counters exposed by Envoy stats
- Alert on sustained increases in ext_authz.denied counters paired with worker crashes
- Forward Envoy stderr and crash logs to centralized logging for correlation across proxy fleets
How to Mitigate CVE-2026-50572
Immediate Actions Required
- Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 depending on your deployed branch
- Inventory all Envoy instances, including sidecars managed by service meshes such as Istio, and prioritize those using the HTTP ext_authz filter
- Restart affected proxies after upgrade to ensure the patched binary is active
Patch Information
The fix is delivered in Envoy releases v1.36.10, v1.37.6, v1.38.4, and v1.39.1. The upstream commits (8dacef3, a4908562, c1b29534, c524571f) reset callbacks_ before invoking the callback. See the Envoy Security Advisory GHSA-q8wp-gf7q-m8cv for full details.
Workarounds
- Temporarily disable the HTTP ext_authz filter if upgrading is not immediately possible
- Switch the ext_authz transport from HTTP to gRPC where the deployment supports it, until patched binaries are rolled out
- Deploy process supervisors and orchestrator health checks to rapidly restart crashed Envoy workers and limit blast radius
# Verify installed Envoy version and confirm patched release
envoy --version
# Example Kubernetes rollout to patched image
kubectl set image deployment/envoy envoy=envoyproxy/envoy:v1.39.1
kubectl rollout status deployment/envoy
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
