Jwt filter crash in the clear route cache with remote JWKs in envoy
Published Sep 19, 2024
7.5
HIGHCVSS 3.1
EPSS 0.40%
Description
Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remote JWKs are used, which requires async header processing; 2. clear_route_cache is enabled on the provider; 3. header operations are enabled in JWT filter, e.g. header to claims feature; 4. the routing table is configured in a way that the JWT header operations modify requests to not match any route. When these conditions are met, a crash is triggered in the upstream code due to nullptr reference conversion from route(). The root cause is the ordering of continueDecoding and clearRouteCache. This issue has been addressed in versions 1.31.2, 1.30.6, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
-
- Version >= 1.29.0, < 1.29.9StatusaffectedConstraints-
- Version >= 1.30.0, < 1.30.6StatusaffectedConstraints-
- Version >= 1.31.0, < 1.31.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Envoyproxy | Envoy | n/a |
|
- ≥ 1.29.0 · < 1.29.9
- ≥ 1.30.0 · < 1.30.6
- ≥ 1.31.0 · < 1.31.2
No data.
OpenShift Service Mesh 2
openshift-service-mesh/istio-cni-rhel8
Affected
OpenShift Service Mesh 2
openshift-service-mesh/pilot-rhel8
Affected
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-cni-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/pilot-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability in Envoy should be considered high-severity rather than moderate due to its potential to cause a complete crash of the service when handling JWT authentication with remote JWKs and asynchronous header processing. In cloud-native environments where Envoy is often used as a critical edge or service proxy, the conditions triggering this crash—such as the combination of route cache clearing, header operations, and JWT authentication—are not uncommon. The impact is significant because the crash occurs during normal request processing, leading to service disruption and downtime.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (GitHub) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 20, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.40% (0.00395) | 31.28th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.37% (0.00372) | 28.77th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00113) | 27.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 19.03th | v3 (v2023.03.01) |
| Sep 20, 2024 | 0.04% (0.00043) | 9.63th | v3 (v2023.03.01) |
References (5)
- https://access.redhat.com/security/cve/CVE-2024-45809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2313686 Issue Tracking
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-wqr5-qmq7-3qw3 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45809
- https://www.cve.org/CVERecord?id=CVE-2024-45809
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-45809 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2313686 | Issue Tracking | |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-wqr5-qmq7-3qw3 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-45809 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-45809 |
Change history (0)
No recorded changes yet.