CVE-2026-26309 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 escapeString off-by-one (GHSA-56cj-wgg3-x943 / WID-SEC-2026-0704)
A vulnerability classified as problematic has been found in envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0. The impacted element is the function Envoy::JsonEscaper::escapeString. Performing a manipulation results in off-by-one.
This vulnerability is identified as CVE-2026-26309. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.