Back

HIGH

Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion

Published Jun 26, 2026

Description

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enabled, processing a specially crafted, highly compressed zstd payload can lead to massive memory allocation. An attacker can exploit this to cause severe memory exhaustion, potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

Affected products

Remediation

Red Hat statement

This vulnerability in Envoy's zstd decompressor is rated as Important, as a remote, unauthenticated attacker can induce a denial of service. By sending a specially crafted zstd payload, an attacker can cause excessive memory allocation, leading to an Out-Of-Memory condition and service disruption for Envoy proxy instances deployed in Red Hat environments.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 26, 2026
Updated Jun 26, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Jun 26, 2026
NVD
Status Analyzed
Modified Jun 29, 2026
Red Hat
Severity Important
Public date Jun 26, 2026