CVE-2024-27919highCWE-390

CVE-2024-27919: high-severity vulnerability in envoyproxy envoy

HTTP/2: memory exhaustion due to CONTINUATION frame flood

Published · Updated

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 87%
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
21 products (26 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4 · OpenShift API for Data Protection · Red Hat Advanced Cluster Management for Kubernetes 2 · Red Hat OpenShift Data Science (RHODS) · Custom Metric Autoscaler operator for Red Hat Openshift · and others 16
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
envoyproxy · envoy