Description
No description is available for this CVE.
Published: n/a
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a remote attacker to trigger a denial‑of‑service condition in Envoy by exploiting HTTP/2’s HPACK compression mechanism combined with a Slowloris‑style traffic pattern. The weakness is related to improper handling of oversized header compression, enabling attackers to exhaust server resources. While a formal description is not available, the reported behavior indicates that an attacker can cause the proxy to refuse service to legitimate clients, resulting in degraded availability for all connections passing through the affected Envoy instance.

Affected Systems

The impacted product is Envoy, a high‑performance edge and service proxy. Versions not listed, so all releases are potentially vulnerable until an official fix is released. Any deployment that relies on Envoy’s HTTP/2 support could be affected.

Risk and Exploitability

The CVSS score of 7.5 places this issue in the medium–high severity range, and the EPSS metric is not available, so the likelihood of exploitation in the wild cannot be quantified. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no publicly known exploits yet. The attack can be performed remotely over an HTTP/2 connection; no local privileges or credentials are required, making it a legitimate concern for exposed services.

Generated by OpenCVE AI on June 11, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Envoy to the latest release that contains a fix for HTTP/2 HPACK handling
  • If upgrading is not possible immediately, disable HTTP/2 support or explicitly refuse HPACK frames to prevent the compression bomb
  • Apply network‑level rate limiting or traffic shaping to mitigate Slowloris‑style attacks, ensuring that inbound connections are throttled before they can saturate server resources

Generated by OpenCVE AI on June 11, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title envoy: envoy: HTTP/2 Remote Denial of Service via HPACK compression bomb and Slowloris-style attack
Weaknesses CWE-409
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-04T00:00:00Z

Links: CVE-2026-47774 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T02:15:27Z

Weaknesses