Back

HIGH

HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy

Published Dec 18, 2024

Description

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Important due to Envoy's improper handling of HTTP 1.1 non-101 1xx responses, potentially leading to downstream failures in networked devices, this issue can disrupt service communication, requiring prompt attention and resolution to maintain network stability.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Dec 18, 2024
Updated Dec 18, 2024
Reserved Nov 19, 2024

CISA Vulnrichment

Updated Dec 18, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Dec 18, 2024
Bugzilla 2333078

ENISA EUVD

Assigner GitHub_M
Published Dec 18, 2024
Updated Dec 18, 2024

GitHub

No data