CVE-2023-27491: Envoy forwards invalid Http2/Http3 downstream headers
Attackers can send specifically crafted HTTP/2 or HTTP/3 requests to trigger parsing errors on HTTP/1 upstream service.
Other sources
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compliant HTTP/1 service may allow malformed requests, potentially leading to a bypass of security policies. This issue is fixed in versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27491?
CVE-2023-27491 is a vulnerability in Envoy, an open source edge and service proxy, where non-compliant HTTP/1 services may allow malformed requests, potentially leading to security issues.
How severe is CVE-2023-27491?
CVE-2023-27491 has a severity score of 9.1, which is considered critical.
Which versions of Envoy are affected by CVE-2023-27491?
Envoy versions prior to 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9 are affected by CVE-2023-27491.
How can I fix CVE-2023-27491?
To fix CVE-2023-27491, you should update Envoy to version 1.26.0, 1.25.3, 1.24.4, 1.23.6, or 1.22.9, or newer.
Where can I find more information about CVE-2023-27491?
More information about CVE-2023-27491 can be found at the following references: [link1], [link2], [link3].