Asymmetric Resource Consumption (Amplification) in envoy - CVE-2026-47774
Published: June 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to asymmetric resource consumption in HTTP/2 downstream request processing when handling specially crafted cookie headers with HPACK decoded-size amplification. A remote attacker can send specially crafted HTTP/2 requests to cause a denial of service.
Flow-control stalling can prolong stream lifetime and delay reclamation of per-stream memory, increasing the effectiveness of the attack.
Affected software
App & API Protector Hybrid
How to mitigate CVE-2026-47774
App & API Protector Hybrid - update to 1.6.1