Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-09T22:50:18.938Z

Updated: 2024-08-01T22:59:32.269Z

Reserved: 2024-01-15T15:19:19.439Z

Link: CVE-2024-23323

cve-icon Vulnrichment

Updated: 2024-08-01T22:59:32.269Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-09T23:15:08.977

Modified: 2024-02-15T04:48:09.937

Link: CVE-2024-23323

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-09T17:00:00Z

Links: CVE-2024-23323 - Bugzilla