First published: Tue Jun 04 2024(Updated: )
Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Envoyproxy Envoy | <1.27.6 | |
Envoyproxy Envoy | >=1.28.0<1.28.4 | |
Envoyproxy Envoy | >=1.29.0<1.29.5 | |
Envoyproxy Envoy | >=1.30.0<1.30.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.