← Back

CVE-2024-53269

nvd nist
Published: Dec 18, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to upgrade may disable Happy Eyeballs and/or change the IP configuration.

Affected (3)

Products: Envoyproxy: Envoy
1 product
Envoy
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Envoyproxy
From 1.30.0 to 1.30.8
From 1.31.0 to 1.31.4
From 1.32.0 to 1.32.2

References (3)

Source: security-advisories@github.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.