CVE-2024-23326
Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-391
- Published
- 2024-06-04
- Last modified
- 2026-03-13
Affected products
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
Weakness type
Related vulnerabilities
- CVE-2026-74900 — openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
- CVE-2025-71325 — picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
- CVE-2024-52316 — Apache Tomcat: Authentication bypass when using Jakarta Authentication API
- CVE-2022-20849 — Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
- CVE-2023-32871 — In DA, there is a possible permission bypass due to an incorrect status check. This could lead to...
- CVE-2023-0572 — Unchecked Error Condition in froxlor/froxlor
- CVE-2022-22160 — Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message
- CVE-2020-14383 — A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server...