CVE-2024-53271
HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy
7.1
HIGH
CVSS 3.1
EPSS 0.03%
Description
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.
How to fix CVE-2024-53271
To remediate CVE-2024-53271, upgrade the affected package to a fixed version below.
- —upgrade to 1.31.5 or later
Is CVE-2024-53271 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.31.0, < 1.31.5, >= 1.32.0, < 1.32.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |