Looking for the vulnerability index of Invicti's legacy products?
Envoy Proxy Improper Handling of Highly Compressed Data (Data Amplification) Vulnerability - CVE-2026-48044 - Vulnerability Database

Envoy Proxy Improper Handling of Highly Compressed Data (Data Amplification) Vulnerability - CVE-2026-48044

High
Reference: CVE-2026-48044
Title: Envoy Proxy Improper Handling of Highly Compressed Data (Data Amplification) Vulnerability
Overview:

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11 1.36.7 1.37.3 and 1.38.1 a vulnerability has been identified in Envoy39s zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enabled processing a specially crafted highly compressed zstd payload can lead to massive memory allocation. An attacker can exploit this to cause severe memory exhaustion potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy. This vulnerability is fixed in 1.35.11 1.36.7 1.37.3 and 1.38.1.