PT-2024-3092 · Envoy+1 · Envoy+1

Adiyamankottai Rajaram

+1

·

Published

2024-04-18

·

Updated

2025-09-04

·

CVE-2024-32475

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.27.5 Envoy versions prior to 1.28.3 Envoy versions prior to 1.29.4 Envoy versions prior to 1.30.1
Description The issue arises when an upstream TLS cluster is used with auto sni enabled and a request contains a host/:authority header longer than 255 characters, causing an abnormal termination of the Envoy process. This occurs because Envoy does not handle errors gracefully when setting SNI for outbound TLS connections, expecting the operation to always succeed. The SNI length is limited to 255 characters per standard.
Recommendations For versions prior to 1.27.5, update to version 1.27.5 or later. For versions prior to 1.28.3, update to version 1.28.3 or later. For versions prior to 1.29.4, update to version 1.29.4 or later. For versions prior to 1.30.1, update to version 1.30.1 or later. As a temporary workaround, consider restricting the length of the host/:authority header to 255 characters or less to prevent abnormal process termination.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

BDU:2024-03289
BIT-ENVOY-2024-32475
CVE-2024-32475
GHSA-3MH5-6Q8V-25WJ

Affected Products

Envoy
Red Os