Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compliant HTTP/1 service may allow malformed requests, potentially leading to a bypass of security policies. This issue is fixed in versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-service-connect-agent-debuginfoUpgrade ecs-service-connect-agent | Jul 14, 2023 | Apr 4, 2023 |
| Amazon_linux_2023 | — | Upgrade ecs-service-connect-agent | Feb 17, 2025 | Apr 4, 2023 |
| Oracle_linux | — | Upgrade kubectlUpgrade olcne-gluster-chartUpgrade olcne-multus-chartUpgrade kubeletUpgrade olcne-extra-modulesUpgrade olcnectlUpgrade olcne-nginxUpgrade kubeadmUpgrade olcne-oci-ccm-chartUpgrade olcne-olm-chartUpgrade olcne-grafana-chartUpgrade olcne-calico-chartUpgrade olcne-istio-chartUpgrade olcne-rook-chartUpgrade olcne-metallb-chartUpgrade olcne-kubevirt-chartUpgrade olcne-prometheus-chartUpgrade olcne-agentUpgrade istioUpgrade olcne-api-serverUpgrade istio-istioctlUpgrade olcne-utils | Jun 2, 2023 | Apr 4, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub