<Vulnerability name="CVE-2026-48044">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-06-26T17:31:37</PublicDate>
    <Bugzilla id="2493649" url="https://bugzilla.redhat.com/show_bug.cgi?id=2493649" xml:lang="en:us">
Envoy: Envoy: Denial of Service via specially crafted zstd payload
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a  vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enabled, processing a specially crafted, highly compressed zstd payload can lead to massive memory allocation. An attacker can exploit this to cause severe memory exhaustion, potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Envoy, an open source edge and service proxy. A remote attacker can exploit this vulnerability by sending a specially crafted, highly compressed zstd payload to an Envoy proxy with zstd decompression enabled. This can lead to massive memory allocation, causing severe memory exhaustion and potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy.
    </Details>
    <Statement xml:lang="en:us">
This vulnerability in Envoy's zstd decompressor is rated as Important, as a remote, unauthenticated attacker can induce a denial of service. By sending a specially crafted zstd payload, an attacker can cause excessive memory allocation, leading to an Out-Of-Memory condition and service disruption for Envoy proxy instances deployed in Red Hat environments.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:service_mesh:3.0::el9">
        <ProductName>Red Hat OpenShift Service Mesh 3.0</ProductName>
        <ReleaseDate>2026-08-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:49705">RHSA-2026:49705</Advisory>
        <Package name="openshift-service-mesh/istio-proxyv2-rhel9">openshift-service-mesh/istio-proxyv2-rhel9:1784908682</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:service_mesh:3.1::el9">
        <ProductName>Red Hat OpenShift Service Mesh 3.1</ProductName>
        <ReleaseDate>2026-08-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:49729">RHSA-2026:49729</Advisory>
        <Package name="openshift-service-mesh/istio-proxyv2-rhel9">openshift-service-mesh/istio-proxyv2-rhel9:1784953556</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:service_mesh:3.2::el9">
        <ProductName>Red Hat OpenShift Service Mesh 3.2</ProductName>
        <ReleaseDate>2026-08-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:49744">RHSA-2026:49744</Advisory>
        <Package name="openshift-service-mesh/istio-proxyv2-rhel9">openshift-service-mesh/istio-proxyv2-rhel9:1784953743</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:service_mesh:3.3::el9">
        <ProductName>Red Hat OpenShift Service Mesh 3.3</ProductName>
        <ReleaseDate>2026-08-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:49765">RHSA-2026:49765</Advisory>
        <Package name="openshift-service-mesh/istio-proxyv2-rhel9">openshift-service-mesh/istio-proxyv2-rhel9:1784908639</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:service_mesh:2">
        <ProductName>OpenShift Service Mesh 2</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>openshift-service-mesh/proxyv2-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-48044
https://nvd.nist.gov/vuln/detail/CVE-2026-48044
https://github.com/envoyproxy/envoy/security/advisories/GHSA-m3p9-47wh-88wg
    </References>
</Vulnerability>