Back

HIGH

envoy: malformed HTTP request without the Host header may cause abnormal termination of the Envoy process

Published Dec 13, 2019

Description

An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 13, 2019
Updated Aug 5, 2024
Reserved Nov 8, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Dec 10, 2019
Bugzilla 1773449

ENISA EUVD

Assigner mitre
Published Dec 13, 2019
Updated Aug 5, 2024

GitHub

No data