← Back

CVE-2024-53271

nvd nist
Published: Dec 18, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Exploitability: 2.8 / Impact: 4.2
Source: security-advisories@github.com (Secondary)

Description

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

Affected (2)

Products: Envoyproxy: Envoy
1 product
Envoy
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Envoyproxy
From 1.31.0 to 1.31.5
From 1.32.0 to 1.32.3

References (3)

Source: security-advisories@github.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.