Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
Published Apr 4, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.73%
Description
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, escalation of privileges is possible when `failure_mode_allow: true` is configured for `ext_authz` filter. For affected components that are used for logging and/or visibility, requests may not be logged by the receiving service.
When Envoy was configured to use ext_authz, ext_proc, tap, ratelimit filters, and grpc access log service and an http header with non-UTF-8 data was received, Envoy would generate an invalid protobuf message and send it to the configured service. The receiving service would typically generate an error when decoding the protobuf message. For ext_authz that was configured with ``failure_mode_allow: true``, the request would have been allowed in this case. For the other services, this could have resulted in other unforeseen errors such as a lack of visibility into requests.
As of versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy by default sanitizes the values sent in gRPC service calls to be valid UTF-8, replacing data that is not valid UTF-8 with a `!` character. This behavioral change can be temporarily reverted by setting runtime guard `envoy.reloadable_features.service_sanitize_non_utf8_strings` to false. As a workaround, one may set `failure_mode_allow: false` for `ext_authz`.
Affected products
-
- Version < 1.22.9StatusaffectedConstraints-
- Version >= 1.23.0, < 1.23.6StatusaffectedConstraints-
- Version >= 1.24.0, < 1.24.4StatusaffectedConstraints-
- Version >= 1.25.0, <1.25.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Envoyproxy | Envoy | n/a |
|
- < 1.22.9
- ≥ 1.23.0 · < 1.23.6
- ≥ 1.24.0 · < 1.24.4
- ≥ 1.25.0 · < 1.25.3
No data.
Red Hat OpenShift Service Mesh 2.2 for RHEL 8
openshift-service-mesh/proxyv2-rhel8:2.2.9-2
Fixed · RHSA-2023:4623
OpenShift Service Mesh 2.1
servicemesh-proxy
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Service Mesh 2.2 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8:2.2.9-2 | Fixed | RHSA-2023:4623 |
| OpenShift Service Mesh 2.1 | servicemesh-proxy | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 other sources (GitHub, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 11, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.73% (0.00731) | 52.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.73% (0.00731) | 49.30th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00035) | 6.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.28% (0.00282) | 69.38th | v3 (v2023.03.01) |
| May 6, 2024 | 0.23% (0.00228) | 60.78th | v3 (v2023.03.01) |
| Apr 10, 2024 | 0.18% (0.00185) | 55.14th | v3 (v2023.03.01) |
| Mar 4, 2024 | 0.12% (0.00119) | 44.96th | v3 (v2023.03.01) |
| May 6, 2023 | 0.10% (0.00104) | 41.30th | v3 (v2023.03.01) |
| Apr 12, 2023 | 0.14% (0.00142) | 48.48th | v3 (v2023.03.01) |
| Apr 5, 2023 | 0.04% (0.00043) | 7.01th | v3 (v2023.03.01) |
References (5)
- https://access.redhat.com/security/cve/CVE-2023-27488 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2182156 Issue Tracking
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-9g5w-hqr3-w2ph x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-27488
- https://www.cve.org/CVERecord?id=CVE-2023-27488
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-27488 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2182156 | Issue Tracking | |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-9g5w-hqr3-w2ph | x_refsource_CONFIRMExploitMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-27488 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-27488 |
Change history (0)
No recorded changes yet.