Back

HIGH

envoy: Resource exhaustion when accepting too many connections

Published Jul 1, 2020

Description

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

Affected products

Remediation

Red Hat statement

A uncontrolled resource consumption vulnerability was found in Envoy. An attacker can initiate too many connections to the proxy potentially exhausting file descriptors and/or memory resulting in a denial of service.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 1, 2020
Updated Aug 4, 2024
Reserved Feb 6, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 30, 2020
ENISA EUVD
Assigner mitre
Published Jul 1, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-29511