7.5
CVSSv3

CVE-2021-32778

Published: 24/08/2021 Updated: 15/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An uncontrolled resource consumption vulnerability was found in envoyproxy/envoy. When envoy handles a large number of HTTP/2 requests which open and then reset the connection, it can cause excessive CPU usage. This flaw allows an malicious user to cause a denial of service on the proxy. The highest threat from this vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

envoyproxy envoy 1.19.0

envoyproxy envoy

Vendor Advisories

An uncontrolled resource consumption vulnerability was found in envoyproxy/envoy When envoy handles a large number of HTTP/2 requests which open and then reset the connection, it can cause excessive CPU usage This flaw allows an attacker to cause a denial of service on the proxy The highest threat from this vulnerability is to system availabilit ...
Envoy, as used by Istio before version 1111, contains a remotely exploitable vulnerability where an Envoy client opening and then resetting a large number of HTTP/2 requests could lead to excessive CPU consumption ...