#VU35101 Infinite loop in envoy - CVE-2019-18836
Published: November 11, 2019 / Updated: August 8, 2020
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."