GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: duplicate Host headers escape request header limits and let a client OOM-kill the proxy

CVSS 7.5CVE-2026-73550Container, Kubernetes & orchestrationcurated

Impact

Envoy copies each decoded HTTP/2 Host value before discarding it when :authority is already set. The discarded copy never goes through saveHeader, so neither its bytes nor its count count against the configured request header limits. Using HPACK indexing, a client can reference one large Host value many times across a small number of streams and drive header-copy allocation until the proxy is OOM-killed. Distinct from CVE-2026-73513: this one is downstream, unauthenticated, and hits the default codec path rather than oghttp2. On a GPU cluster the practical effect is a tenant-facing ingress or mesh proxy that a single unauthenticated client can knock out, cutting off inference traffic behind it; container memory limits make the kill easier, not harder.

Who can reach it

Any unauthenticated client that can open HTTP/2 connections to an Envoy listener - internet-facing ingress or any in-cluster caller reaching a sidecar.

What to do

Upgrade to Envoy 1.36.10, 1.37.6, 1.38.4 or 1.39.1. Rolling restart of proxies / sidecar redeploy. Lowering header limits does not help, since the abusive copies are the ones that bypass accounting; until patched, rely on upstream rate limiting and connection limits.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.