Improper HTTP Response Handling in Envoy Proxy by Envoy
CVE-2024-53271

Currently unrated

Key Information:

Vendor

Envoy

Vendor
CVE Published:
18 December 2024

What is CVE-2024-53271?

Envoy, a high-performance edge and service proxy, contains a vulnerability due to improper handling of HTTP/1.1 non-101 1xx responses. This flaw can result in failure of downstream network devices, potentially disrupting service operations. The issue has been resolved in versions 1.31.5 and 1.32.3, and users are strongly urged to upgrade their installations to mitigate any associated risks. Currently, there are no known workarounds available for this security concern.

References

Timeline

  • Vulnerability published

.