Input validation error in envoy - #VU145855
Published: December 17, 2020 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause incorrect logging of the downstream address.
The vulnerability exists due to improper input validation in tcp-proxy when processing proxy-protocol connection information. A remote attacker can send crafted proxy-protocol data to cause incorrect logging of the downstream address.