envoy is vulnerable to Resource Exhaustion
75
High Risk
Envoy HTTP/2 request handling can be abused with HPACK indexed references and split cookie fields to amplify small wire input into large server-side header allocations. A client can then advertise a zero-byte response flow-control window and drip updates to keep those allocations alive. Affected servers can suffer remote memory exhaustion and availability loss from a small number of connections. No patched Envoy release was available in the checked evidence.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled.
envoy is vulnerable to Resource Exhaustion in versions 0.0.1 - 1.38.0.
Disable HTTP/2 or front Envoy with a proxy that enforces a hard cap on header count per request until a patched release is available.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant