Envoy
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*
- 1.17.1
- 1.16.2
- 1.15.3
- 1.14.6
A denial-of-service vulnerability exists in Envoy version 1.14.0. When an empty METADATA map is sent in an HTTP/2 request, it triggers a reachable assertion, causing the application to crash. This issue is remotely exploitable.
Exploitation of this vulnerability leads to a crash of the Envoy process, causing a denial-of-service condition.
To reproduce this vulnerability, send an HTTP/2 request with a METADATA frame that contains an empty METADATA map. This will cause Envoy to crash.
Users can upgrade to Envoy versions 1.14.7, 1.15.4, 1.16.3, 1.17.2, or 1.18.0 to address this vulnerability. Alternatively, HTTP/2 Metadata frame support can be disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.