Asymmetric Resource Consumption (Amplification) in envoy - CVE-2026-47774
Published: June 4, 2026
envoy
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to asymmetric resource consumption in HTTP/2 downstream request processing when handling specially crafted cookie headers with HPACK decoded-size amplification. A remote attacker can send specially crafted HTTP/2 requests to cause a denial of service.
Flow-control stalling can prolong stream lifetime and delay reclamation of per-stream memory, increasing the effectiveness of the attack.