Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-057

A series of security vulnerabilities were found in Envoy Proxy, a software used in Google Cloud's service mesh infrastructure. These issues could potentially affect the stability or security of environments using Envoy. The severity ranges from moderate to high. Google Cloud recommends reviewing the related Cloud Service Mesh security bulletin for detailed guidance and instructions on how to address these vulnerabilities.

Published 2/9/2026, 6:28:49 pmVerified 3/9/2026, 1:21:16 pmRevision 1
Google Cloud unrated network security advisory visual

In plain language

What this advisory means

A series of security vulnerabilities were found in Envoy Proxy, a software used in Google Cloud's service mesh infrastructure. These issues could potentially affect the stability or security of environments using Envoy. The severity ranges from moderate to high. Google Cloud recommends reviewing the related Cloud Service Mesh security bulletin for detailed guidance and instructions on how to address these vulnerabilities.

Technical explanation

How the issue affects the environment

Multiple security flaws were identified in Envoy Proxy, a proxy component frequently deployed within Google Cloud's service mesh architecture. The vulnerabilities span a range of issues impacting Envoy's request processing, such as denial of service risks and other security weaknesses. These flaws are cataloged under several CVE identifiers, including CVE-2026-73513, CVE-2026-73552, CVE-2026-73512, and others. The vulnerabilities can lead to denial of service or potentially more severe impacts depending on exploit. Google Cloud advises consulting the Cloud Service Mesh security bulletin for comprehensive remediation steps and further technical details.

Operational impact

Why teams should care

Organizations using Google Cloud's service mesh technologies that rely on Envoy Proxy may face risks including service disruption or compromise if these vulnerabilities are exploited. This could affect application availability or data security. Addressing these issues helps maintain trust, regulatory compliance, and smooth business operations by preventing potential attacks against the service mesh infrastructure.

Immediate action

Google Cloud recommends reviewing and following the instructions in the Cloud Service Mesh security bulletin to address the identified vulnerabilities in Envoy Proxy. Specific remediation steps are detailed in that bulletin.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Security bulletin from Google Cloud dated 2026-08-26 announcing multiple vulnerabilities in Envoy Proxy
  • Listing of specific CVEs related to Envoy Proxy vulnerabilities
  • Reference to Cloud Service Mesh security bulletin for instructions and additional details
  • Severity assessments described as moderate to high

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source