Plan
active
Envoy v1.37.6 patches nine CVEs including UAF and HTTP/2 crash bugs
- Platform/SRE — Plan: Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.