Unrated severityNVD Advisory· Published Jun 4, 2024· Updated Aug 2, 2024
Envoy can crash due to uncaught nlohmann JSON exception
CVE-2024-34363
Description
Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.
Affected products
1- Range: >= 1.30.0, <= 11.30.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/envoyproxy/envoy/security/advisories/GHSA-g979-ph9j-5gg4mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.