Impact
The advisory refers to Envoy and the title indicates a memory exhaustion issue caused by discarded Host headers that are not counted against configured limits. No additional description is provided, so the exact behavior or extent of the problem is not documented beyond this statement.
Affected Systems
Envoy Proxy (all releases are potentially affected, specific versions are not identified in the advisory).
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. No EPSS score is reported and it is not listed in CISA’s KEV catalog. The details do not specify an attack vector; based on the topic of the vulnerability, it is inferred that a remote attacker could interact with a public‑facing Envoy instance over HTTP/2 to exploit the memory exhaustion, but this inference is not confirmed by the advisory.
OpenCVE Enrichment