Plan
active
Envoy v1.38.4 patches 9+ CVEs including HTTP/3 UAF and HTTP/2 crash bugs
- Platform/SRE — Plan: Envoy is a common data-plane component in service meshes and ingress layers; this patch addresses a use-after-free in HTTP/3, process-termination bugs in HTTP/2, and multiple URL-normalization bypasses. No KEV listing or known active exploitation, so no hard deadline, but upgrade to v1.38.4 should be scheduled this sprint for any fleet running Envoy.
- CI/CD — Skip
- Leader — Skip
- Signals: CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.