Impact
Higress before version 2.2.4 crashes when processing a Cookie header segment that contains no equals sign, and the accompanying plugin wrapper recovers and issues a continue action. That action bypasses the AI token rate limiting that is intended to constrain expensive model backend calls, allowing an unauthenticated attacker to send a crafted HTTP request and avoid all rate‑limit checks. The result is uncontrolled access to costly backend services, which can lead to denial of service or significant cost escalation.
Affected Systems
The vulnerability affects the higress‑group/higress product for all releases prior to and including 2.2.3. The ai‑token‑ratelimit plugin must be upgraded to version 2.2.4 or later to incorporate the patch that protects against malformed Cookie headers.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity, while the EPSS score below 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an unauthenticated HTTP client to send a request containing a Cookie header without an equals sign to the Higress gateway; no privileges or additional conditions are needed beyond network connectivity.
OpenCVE Enrichment