Description
An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.
Published: 2019-12-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8539 An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.
History

No history.

Subscriptions

Envoyproxy Envoy
Redhat Service Mesh
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:02:39.849Z

Reserved: 2019-11-08T00:00:00.000Z

Link: CVE-2019-18838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-13T13:15:11.443

Modified: 2024-11-21T04:33:41.103

Link: CVE-2019-18838

cve-icon Redhat

Severity : Important

Publid Date: 2019-12-10T18:00:00Z

Links: CVE-2019-18838 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses