Bugzilla – Bug 1221398
VUL-0: CVE-2024-27919: envoy: HTTP/2 CONTINUATION frames can be utilized for DoS attacks
Last modified: 2024-04-04 07:10:28 UTC
CVE: CVE-2024-27919 ID: VU#421644.7 Case: VU#421644: HTTP/2 CONTINUATION frames can be utilized for DoS attacks Date Added: 2024-03-14 Description: HTTP/2 CONTINUATION frames without the END_HEADERS flag set can be sent in a continuous stream by an attacker to a target implementation running Envoy, which will not properly append header information in memory, causing an OOM crash.
CRD: 2024-03-28
CRD: 2024-04-04
is public https://kb.cert.org/vuls/id/421644
we are not shippig envoy anymore