CVE-2023-35945
Last modified
CVE-2023-35945 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if connection is already marked for not sending more requests due to `GOAWAY` frame. The clean-up code is right after the return statement, causing memory leak. Denial of service through memory exhaustion. This vulnerability was patched in versions(s) 1.26.3, 1.25.8, 1.24.9, 1.23.11.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Envoyproxy | Envoy | < 1.23.11 |
| Envoyproxy | Envoy | >= 1.24.0, < 1.24.9 |
| Envoyproxy | Envoy | >= 1.25.0, < 1.25.8 |
| Envoyproxy | Envoy | >= 1.26.0, < 1.26.3 |
| Nghttp2 | Nghttp2 | < 1.55.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35945?
How severe is CVE-2023-35945?
How do I fix CVE-2023-35945?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-35939GLPI is a free asset and IT management software package. Sta…8.1
- CVE-2023-35940GLPI is a free asset and IT management software package. Sta…7.5
- CVE-2023-35941Envoy is an open source edge and service proxy designed for …9.8
- CVE-2023-35942Envoy is an open source edge and service proxy designed for …6.5
- CVE-2023-35943Envoy is an open source edge and service proxy designed for …7.5
- CVE-2023-35944Envoy is an open source edge and service proxy designed for …5.3
- CVE-2023-35946Gradle is a build tool with a focus on build automation and …5.5
- CVE-2023-35947Gradle is a build tool with a focus on build automation and …8.1
- CVE-2023-35948Novu provides an API for sending notifications through multi…6.1
- CVE-2023-35949Multiple stack-based buffer overflow vulnerabilities exist i…7.8
- CVE-2023-3595 Where this vulnerability exists in the Rockwell Automation …9.8
- CVE-2023-35950Multiple stack-based buffer overflow vulnerabilities exist i…7.8
Are you affected by CVE-2023-35945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
