Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy when the specified host header is missing in the request headers. This vulnerability is fixed in 1.37.5 and 1.38.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HEnvoyproxy Envoy
APPEnvoyproxy1.37.0 – 1.37.5 (excl.)1.38.0 – 1.38.3 (excl.)
Related vulnerabilities
Envoy OAuth filter: pominięcie walidacji access tokena umożliwia nieautoryzowany dostęp
Envoy 1.12.0: zapis poza buforami żądania HTTP/2 prowadzący do RCE lub bypass ACL
Bypass mechanizmów kontroli dostępu przez białe znaki w nagłówkach HTTP w Envoy
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...
Envoy Proxy: stack overflow przy głęboko zagnieżdżonych obiektach JSON