CVE-2026-73512 Overview
CVE-2026-73512 is a use-after-free vulnerability [CWE-416] in Envoy, the open source edge and service proxy widely deployed for cloud-native applications. The flaw resides in the HttpDatagramHandler component used when the HTTP/3 Capsule Protocol is enabled. HttpDatagramHandler caches a pointer to the current RequestDecoder, but stream recreation paths such as internal redirects replace the ActiveStream and update EnvoyQuicServerStream without refreshing the cached pointer. A subsequent HTTP/3 datagram triggers decodeData through the freed decoder, causing invalid virtual dispatch and a process crash. Envoy versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1 are affected.
Critical Impact
A remote, unauthenticated attacker can crash an Envoy proxy process by sending a specifically timed sequence of HTTP/3 frames, resulting in denial of service for all traffic routed through the proxy.
Affected Products
- Envoy versions prior to 1.36.10
- Envoy versions prior to 1.37.6
- Envoy versions prior to 1.38.4 and 1.39.1
Discovery Timeline
- 2026-09-21 - CVE-2026-73512 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-73512
Vulnerability Analysis
The vulnerability is a heap use-after-free in Envoy's HTTP/3 datagram handling path. When the Capsule Protocol is enabled on a stream, EnvoyQuicClientStream::useCapsuleProtocol() (and the corresponding server path) constructs an HttpDatagramHandler and stores a raw pointer to the current RequestDecoder via setStreamDecoder(getResponseDecoder()). This cached pointer becomes stale when the stream is recreated through paths such as internal redirects, because the recreation replaces the underlying ActiveStream and updates EnvoyQuicServerStream without notifying the handler.
When a subsequent HTTP/3 datagram arrives, HttpDatagramHandler::decodeCapsule invokes decodeData on the freed decoder. The resulting virtual dispatch operates on a destroyed object, producing memory corruption and a process crash. Because Envoy typically terminates the entire process on such faults, all connections handled by that worker are dropped.
Root Cause
The root cause is a lifetime mismatch between the cached decoder pointer in HttpDatagramHandler and the stream objects owned by Envoy's HTTP filter chain. The handler holds a non-owning reference that is never invalidated when stream recreation occurs, violating the ownership assumptions that Envoy's filter architecture relies on.
Attack Vector
Exploitation requires that HTTP/3 datagrams and the Capsule Protocol are enabled on the Envoy listener, and that the request enters a stream-recreation path such as an internal redirect. The attack is network-based, requires no authentication, and requires no user interaction. The condition is a specifically timed sequence of HTTP/3 frames that triggers stream recreation before a datagram is processed.
// Patch: source/common/quic/envoy_quic_client_stream.cc
// connect-udp".
void EnvoyQuicClientStream::useCapsuleProtocol() {
http_datagram_handler_ = std::make_unique<HttpDatagramHandler>(*this);
- http_datagram_handler_->setStreamDecoder(getResponseDecoder());
+ http_datagram_handler_->setStreamDecoderProvider(
+ [this]() -> Http::StreamDecoder* { return getResponseDecoder(); });
RegisterHttp3DatagramVisitor(http_datagram_handler_.get());
}
#endif
Source: Envoy commit 29dbaae. The fix replaces the cached raw pointer with a provider lambda that resolves the current ResponseDecoder at call time, ensuring the handler always uses the live decoder after stream recreation.
Detection Methods for CVE-2026-73512
Indicators of Compromise
- Unexpected Envoy worker process crashes or restarts correlated with HTTP/3 traffic and Capsule Protocol usage.
- Crash logs referencing HttpDatagramHandler, decodeCapsule, or decodeData on freed memory.
- Sudden bursts of HTTP/3 CONNECT-UDP requests followed by internal redirects and datagram frames from the same client.
Detection Strategies
- Enable AddressSanitizer or equivalent memory-safety instrumentation in non-production Envoy builds to surface use-after-free conditions during testing.
- Alert on abnormal Envoy process restart rates and correlate with HTTP/3 listener metrics such as http3.downstream.rx.quic_connection_close_error_code.
- Inspect access logs for requests that combine internal redirects with HTTP/3 CONNECT-UDP or Capsule Protocol usage from untrusted clients.
Monitoring Recommendations
- Track Envoy version inventory across the fleet and flag any instance below 1.36.10, 1.37.6, 1.38.4, or 1.39.1.
- Monitor QUIC and HTTP/3 error counters, worker restart counts, and connection drop rates for anomalies.
- Forward Envoy stderr and crash dumps to centralized logging for signature analysis.
How to Mitigate CVE-2026-73512
Immediate Actions Required
- Upgrade Envoy to 1.36.10, 1.37.6, 1.38.4, or 1.39.1 depending on the deployed minor version.
- If upgrade is not immediately feasible, disable HTTP/3 datagrams and the Capsule Protocol on affected listeners.
- Audit route configurations to identify listeners that combine HTTP/3, Capsule Protocol, and internal redirect behaviors.
Patch Information
The issue is fixed by commits 29dbaae, 8549516, c0e46da, and f2417ee. Patched releases are available: v1.36.10, v1.37.6, v1.38.4, and v1.39.1. Full details are in GHSA-r6j2-mrm5-72mg.
Workarounds
- Disable HTTP/3 support on public-facing Envoy listeners until patched binaries are deployed.
- Disable the Capsule Protocol or CONNECT-UDP handling on affected listeners to prevent HttpDatagramHandler instantiation.
- Remove or restrict route configurations that trigger internal redirects on HTTP/3 traffic paths.
# Configuration example: disable HTTP/3 on an Envoy listener as a temporary workaround
# In the listener configuration, remove the QUIC transport socket and udp_listener_config,
# leaving only the TCP-based HTTP/2 or HTTP/1.1 filter chain in place.
envoy --config-path /etc/envoy/envoy.yaml --disable-extensions envoy.quic.crypto_stream.server.quiche,envoy.quic.proof_source.filter_chain
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
