CVE-2026-48042CWE-1124

Envoy: Stack overflow in destructor of highly nested JSON

High · published June 26, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
44.4
In the wild
Unconfirmed
What it is

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00557 · 44.4th percentile
Weakness
CWE-1124 · Excessively Deep Nesting
Published
2026-06-26T17:29Z
EPSS history
Timeline
  • 26 JUN 17:29Z
    Envoy: Stack overflow in destructor of highly nested JSON
    cvelistv5