Back to Database
Status published
Medium
CVE-2024-34364
Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response
Vulnerability Description
Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-34364
Credits & Attribution
No credits recorded in the NVD database.
More from envoyproxy
View All →CVE-2025-66220
Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Medium
5
CVE-2025-64763
Envoy forwards early CONNECT data in TCP proxy mode
Low
3.7
CVE-2025-64527
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Medium
6.5
CVE-2025-62504
Envoy Lua filter use-after-free when oversized rewritten response body causes crash
Medium
6.5
CVE-2025-62409
Envoy allows large requests and responses to cause TCP connection pool crash
Medium
6.6
Affected Vendor
envoyproxy
View all reports →Affected Software
envoy
Vulnerable Versions:
>= 1.30.0, <= 11.30.1, >= 1.29.0, <= 1.29.4, >= 1.28.0, <= 1.28.3, <= 1.27.5
Timeline
Official Publish:
June 4th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H