High severity8.3OSV Advisory· Published Apr 25, 2019· Updated Jun 17, 2026
CVE-2019-9900
CVE-2019-9900
Description
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4v1.0.0, v1.1.0, v1.2.0, …+ 2 more
- (no CPE)range: v1.0.0, v1.1.0, v1.2.0, …
- cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*range: <=1.9.0
- (no CPE)range: <=1.9.0
- cpe:2.3:a:redhat:openshift_service_mesh:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/envoyproxy/envoy/issues/6434nvdExploitIssue TrackingThird Party Advisory
- github.com/envoyproxy/envoy/security/advisories/GHSA-x74r-f4mw-c32hnvdExploitMitigationThird Party Advisory
- access.redhat.com/errata/RHSA-2019:0741nvdThird Party Advisory
- www.envoyproxy.io/docs/envoy/v1.9.1/intro/version_historynvdRelease NotesVendor Advisory
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.