CVE-2024-23323CWE-1176CWE-400

Excessive CPU usage when URI template matcher is configured using regex in Envoy

Medium · published February 9, 2024

CVSS v3.1
4.3
EPSS
1%
Percentile
41.2
In the wild
Unconfirmed
What it is

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00504 · 41.2th percentile
Weaknesses
CWE-1176 · Inefficient CPU Computation; CWE-400 · Uncontrolled Resource Consumption
Published
2024-02-09T22:50Z
EPSS history
Timeline
  • 09 FEB 22:50Z
    Excessive CPU usage when URI template matcher is configured using regex in Envoy
    cvelistv5