Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.
The product does not properly control the allocation and maintenance of a limited resource.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/envoyproxy/envoy/security/advisories/GHSA-xcj3-h7vf-fw26 | third party advisory exploit |