Looking for the vulnerability index of Invicti's legacy products?
Envoy Proxy Use After Free Vulnerability - CVE-2026-47207 - Vulnerability Database

Envoy Proxy Use After Free Vulnerability - CVE-2026-47207

Medium
Reference: CVE-2026-47207
Title: Envoy Proxy Use After Free Vulnerability
Overview:

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13 1.36.9 1.37.5 and 1.38.3 Envoy crashes if an ext_proc server sends a single gRPC message containing multiple specially crafted ProcessingResponse messages. This can occur when the first response in the batch causes the gRPC stream object to be destroyed leading to a use-after-free error when Envoy attempts to process subsequent responses in the same gRPC message. This vulnerability is fixed in 1.35.13 1.36.9 1.37.5 and 1.38.3.