CVE-2026-48042
Envoy: Stack overflow in destructor of highly nested JSON
7.5
HIGH
CVSS 3.1
EPSS 0.56%
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
How to fix CVE-2026-48042
To remediate CVE-2026-48042, upgrade the affected package to a fixed version below.
- —upgrade to 1.35.11 or later
Is CVE-2026-48042 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.35.11, >= 1.36.0, < 1.36.7, >= 1.37.0, < 1.37.3, >= 1.38.0, < 1.38.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |