Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alyssa Wilk

Researcher fromGoogle
#15702of 53,633
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2020-20255
7.5
2020-03-04
Cncf · Envoy · CVE-2020-8661
**Name of the Vulnerable Software and Affected Versions** CNCF Envoy versions prior to 1.13.1 **Description** The issue is related to excessive memory consumption when responding internally to pipelined requests. **Recommendations** For versions prior to 1.13.1, update to version 1.13.1 or later to resolve the issue.
PT-2019-15674
9.8
2019-12-13
Envoy · Envoy · CVE-2019-18802
**Name of the Vulnerable Software and Affected Versions** Envoy version 1.12.0 **Description** An issue was discovered where an untrusted remote client can send an HTTP header, such as the `Host` header, with whitespace after the header content. This allows the client to bypass matchers, for example, by sending a `Host` header with a value of "example.com " to bypass an "example.com" matcher. **Recommendations** For Envoy version 1.12.0, as a temporary workaround, consider restricting the use of HTTP headers with whitespace after the header content until a patch is available.