Database/Container, Kubernetes & orchestration
Envoy: HTTP/2 request writes to the heap outside request buffers when the upstream is HTTP/1
CVSS 9.8CVE-2019-18801Container, Kubernetes & orchestrationcurated
Impact
HTTP/2 request writes to the heap outside request buffers when the upstream is HTTP/1; potential RCE in the proxy
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy; for a mesh this means restarting every sidecar, which restarts tenant pods
References
Related entries
- Envoy: Header whitespace handling enables request smuggling and authorization bypassCVE-2019-18802 · EnvoyCritical
- Envoy: ext-authz header handling flaw allows bypassing the external authorization serviceCVE-2021-32777 · EnvoyHigh
- Envoy: URI fragment treated as part of the pathCVE-2021-32779 · EnvoyHigh
- Envoy: Processing continues after a local reply, causing undefined behaviourCVE-2021-32781 · EnvoyHigh
- Envoy: Malicious client constructs permanently valid credentials in the OAuth filterCVE-2023-35941 · EnvoyHigh
- Envoy: JWT with an issuer absent from the provider list bypasses JWT authenticationCVE-2021-21378 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.