Database/Container, Kubernetes & orchestration
Envoy: Decompressor accumulates unbounded data
CVSS 7.5CVE-2022-29225Container, Kubernetes & orchestrationcurated
Impact
Decompressor accumulates unbounded data; memory exhaustion of the proxy
Who can reach it
Unauthenticated network
What to do
Upgrade Envoy
References
Related entries
- Envoy: "HTTP/2 Rapid Reset": stream-cancellation flood exhausts server resourcesCVE-2023-44487 · EnvoyHigh
- Envoy: Stream-management bugs in the default oghttp HTTP/2 codecCVE-2024-45807 · EnvoyHigh
- Envoy: Load-shed path assumes an active request existsCVE-2024-53270 · EnvoyHigh
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
- Envoy: Envoy accepts any peer certificate rather than restricting to configured CAsCVE-2022-21657 · EnvoyMedium
- Envoy: No URL path normalization, so `something/../admin` bypasses access controlCVE-2019-9901 · EnvoyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.