CVE-2024-27919: high-severity vulnerability in envoyproxy envoy
HTTP/2: memory exhaustion due to CONTINUATION frame flood
Published · Updated
43Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 87%
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
21 products (26 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4 · OpenShift API for Data Protection · Red Hat Advanced Cluster Management for Kubernetes 2 · Red Hat OpenShift Data Science (RHODS) · Custom Metric Autoscaler operator for Red Hat Openshift · and others 16
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption. This can lead to denial of service through memory exhaustion. Users should upgrade to versions 1.29.2 to mitigate the effects of the CONTINUATION flood. Note that this vulnerability is a regression in Envoy version 1.29.0 and 1.29.1 only. As a workaround, downgrade to version 1.28.1 or earlier or disable HTTP/2 protocol for downstream connections.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
envoyproxy · envoyRelated CVEs — envoyproxy envoy
In the same product, most dangerous first.
CVE-2024-30255MEDIUMHTTP/2: CPU exhaustion due to CONTINUATION frame floodEPSS 87.8%CVE-2021-29492HIGHBypass of path matching rules using escaped slash charactersEPSS 66.2%CVE-2021-32777HIGHIncorrect concatenation of multiple value request headers in ext-authz extensionEPSS 3.3%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%CVE-2021-32781HIGHContinued processing of requests after locally generated responseEPSS 1.3%
References
https://github.com/envoyproxy/envoy/commit/57a02565532c18eb9df972a3e8974be3ae59f2d5https://github.com/envoyproxy/envoy/security/advisories/GHSA-gghf-vfxp-799rhttps://www.kb.cert.org/vuls/id/421644http://www.openwall.com/lists/oss-security/2024/04/03/16http://www.openwall.com/lists/oss-security/2024/04/05/3