Kestrel
대시보드로 돌아가기
CVE-2026-48706MEDIUM· 5.9MITRENVD대응게시일: 2026. 06. 26.수정일: 2026. 06. 29.CNA: security-advisories@github.comAnalyzed

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3

Memory-Corruption

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
5.9medium

이론적 심각도 점수

EPSS
0.4%상위 69.7%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도높음
필요 권한불필요
사용자 상호작용불필요
범위불변
영향
기밀성 영향없음
무결성 영향없음
가용성 영향높음
버전별 점수
CVSS 3.15.9MEDIUM· 악용성 2.2· 영향도 3.6
CVSS 3.17.5HIGH· 악용성 3.9· 영향도 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

약점 (CWE)

  • CWE-120

    고전적 버퍼 오버플로 — 크기 검사 없이 복사해 버퍼를 넘침.

상세 설명

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionally long statistic names (e.g., >16KiB). During formatting, TcpStatsdSink reserves a single contiguous memory slice of 16KiB (FLUSH_SLICE_SIZE_BYTES). If formatting a single metric exceeds the remaining capacity, the flusher initiates a buffer rotation but incorrectly continues to allocate another fixed 16KiB slice. If an attacker can trigger a statistic name longer than 16KiB—for example, by sending an HTTP or gRPC request with an extremely long request path (:path) that is recorded by the grpc_stats filter configured with stats_for_all_methods: true—the flusher will attempt to copy the metric name using memcpy operations beyond the allocated heap buffer boundaries. This leads to a heap write overflow, which can cause immediate denial-of-service (process crash) or potential remote code execution (RCE). This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.

영향받는 제품·버전

  • envoyproxy envoy1.34.0 - 1.35.13
    other
  • envoyproxy envoy1.36.0 - 1.36.9
    other
  • envoyproxy envoy1.37.0 - 1.37.5
    other
  • envoyproxy envoy1.38.0 - 1.38.3
    other

영향받는 구성 (CPE) 1

  • envoyproxy envoy≥ 1.34.0 < 1.35.13cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*

참고 자료 1

링크 내용 불러오는 중…