Unrated severityNVD Advisory· Published Sep 19, 2024· Updated Sep 20, 2024
oghttp2 crash on OnBeginHeadersForStream in envoy
CVE-2024-45807
Description
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using oghttp as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the oghttp2 by default. The impact of this issue is that envoy will crash. This issue has been addressed in release version 1.31.2. All users are advised to upgrade. There are no known workarounds for this issue.
Affected products
1- Range: >= 1.31.0, < 1.31.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/envoyproxy/envoy/security/advisories/GHSA-qc52-r4x5-9w37mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.