CVE-2026-48042

Source
https://cve.org/CVERecord?id=CVE-2026-48042
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48042.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48042
Aliases
Downstream
Related
Published
2026-06-26T17:29:14.964Z
Modified
2026-08-12T03:51:44.436991560Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Envoy: Stack overflow in destructor of highly nested JSON
Details

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

Database specific
{
    "cwe_ids": [
        "CWE-1124"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48042.json"
}
References

Affected packages

Git / github.com/envoyproxy/envoy

Affected ranges

Type
GIT
Repo
https://github.com/envoyproxy/envoy
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.18.0"
        },
        {
            "fixed": "1.35.13"
        },
        {
            "introduced": "1.36.0"
        },
        {
            "fixed": "1.36.9"
        },
        {
            "introduced": "1.37.0"
        },
        {
            "fixed": "1.37.5"
        },
        {
            "introduced": "1.38.0"
        },
        {
            "fixed": "1.38.3"
        }
    ]
}

Affected versions

v1.*
v1.18.0
v1.18.1
v1.18.2
v1.19.0
v1.20.0
v1.21.0
v1.22.0
v1.23.0
v1.24.0
v1.25.0
v1.26.0
v1.27.0
v1.28.0
v1.29.0
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.34.0
v1.35.0
v1.35.1
v1.35.10
v1.35.11
v1.35.12
v1.35.2
v1.35.3
v1.35.4
v1.35.5
v1.35.6
v1.35.7
v1.35.8
v1.35.9
v1.36.0
v1.36.1
v1.36.2
v1.36.3
v1.36.4
v1.36.5
v1.36.6
v1.36.7
v1.36.8
v1.37.0
v1.37.1
v1.37.2
v1.37.3
v1.37.4
v1.38.0
v1.38.1
v1.38.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48042.json"