CVE-2019-18836

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/11/2019
Last modified:
07/11/2023

Description

Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:envoyproxy:envoy:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:* 1.3.0 (including) 1.3.3 (including)