CVE-2024-53271

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2024
Last modified:
04/09/2025

Description

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.31.0 (including) 1.31.5 (excluding)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.32.0 (including) 1.32.3 (including)