Resource exhaustion in envoy - #VU135119
Published: June 24, 2026
envoy
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the HTTP/3 QPACK decoder when processing blocked QPACK header blocks in HEADERS frames. A remote attacker can send a syntactically valid HEADERS frame that remains blocked on dynamic table updates to cause a denial of service.
Exploitation requires HTTP/3 to be enabled, support for the QPACK dynamic table, and a non-zero blocked-stream setting.