CVE-2026-26311: Envoy Filter Manager Decode Missing Stop Check
A `FilterManager` decode method iterates over decoder filters using `commonDecodePrefix` without verifying if the filter chain was concurrently stopped. This creates a vulnerability window where incoming frames on a logically aborted or reset HTTP stream still invoke callbacks, potentially leading to a Use-After-Free (UAF) or state-corruption (Zombie Stream
greprules fetch cve-2026-26311-envoy-filter-manager-decode-missing-stop-check --engine opengrepDescription
A `FilterManager` decode method iterates over decoder filters using `commonDecodePrefix` without verifying if the filter chain was concurrently stopped. This creates a vulnerability window where incoming frames on a logically aborted or reset HTTP stream still invoke callbacks, potentially leading to a Use-After-Free (UAF) or state-corruption (Zombie Stream
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0