envoy is vulnerable to Resource Exhaustion
75
High Risk
Envoy's HTTP/2 downstream request processing can be abused with split cookie headers and HPACK decoded-size amplification to bypass intended request header size protections. Cookie fragments are buffered separately and not fully counted before request acceptance, while HPACK limits are enforced on encoded bytes rather than total decoded header size. An unauthenticated remote client can force large per-stream memory allocations and keep them alive under concurrency, potentially causing Envoy to run out of memory and terminate.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 downstream request processing is enabled.
envoy is vulnerable to Resource Exhaustion in versions 0.0.1 - 1.35.10, 1.36.0 - 1.36.6, 1.37.0 - 1.37.2 and 1.38.0 - 1.38.0.
Upgrade the envoy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant