REDHAT-BUG-2493652: High severity Envoy Envoy vulnerability
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTEDSERVERNAME(X:Y)% is used in log format and host related options is specified, like HOSTFIRST, SNIFIRST, it's possible to crash Envoy when the specified host header is missing in the request headers. This vulnerability is fixed in 1.37.5 and 1.38.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.37.5 - Upgrade
Upgrade
envoyproxy/envoyto a version that resolves this vulnerability.Fixed in 1.38.3
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2493652?
The severity of REDHAT-BUG-2493652 is high with a score of 7.
How do I fix REDHAT-BUG-2493652?
To fix REDHAT-BUG-2493652, upgrade Envoy to a version higher than 1.37.5 or 1.38.3.
What components are affected by REDHAT-BUG-2493652?
REDHAT-BUG-2493652 affects Envoy versions from 1.37.0 to 1.37.5 and 1.38.3.
What is the nature of the issue described in REDHAT-BUG-2493652?
The issue in REDHAT-BUG-2493652 can cause Envoy to crash when certain log format options are used.
When was REDHAT-BUG-2493652 published?
REDHAT-BUG-2493652 was published on June 26, 2026.