CVE-2026-26311 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 Filter decodeData use after free (GHSA-84xm-r438-86px / WID-SEC-2026-0704)
A vulnerability identified as critical has been detected in envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0. Affected by this vulnerability is the function FilterManager::decodeData of the component Filter Handler. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-26311. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.