← Vulnerability feed

Vulnerability record · CVE-2024-30255 · published 4 April 2024

CVE-2024-30255: Envoy HTTP/2 CONTINUATION frame flood causes CPU exhaustion

Envoyproxy · Envoy

Envoy's HTTP/2 codec accepts an unlimited number of CONTINUATION frames even after the header map limit is exceeded. An attacker can send CONTINUATION frames without the END_HEADERS bit, driving CPU consumption of roughly one core per 300 Mbit/s of traffic and causing denial of service. The flaw affects Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8.

7.5 CVSS 3.1 High EPSS 88% · top 0.2% CWE-390 · CWE-390
7.5CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the client to send an unlimited number of CONTINUATION frames even after exceeding Envoy's header map limits. This allows an attacker to send a sequence of CONTINUATION frames without the END_HEADERS bit set causing CPU utilization, consuming approximately 1 core per 300Mbit/s of traffic and culminating in denial of service through CPU exhaustion. Users should upgrade to version 1.29.3, 1.28.2, 1.27.4, or 1.26.8 to mitigate the effects of the CONTINUATION flood. As a workaround, disable HTTP/2 protocol for downstream connections.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote, unauthenticated CPU exhaustion with a high EPSS score and a patch available, though not known to be actively exploited.

What it is

Envoy's HTTP/2 codec accepts an unlimited number of CONTINUATION frames even after the header map limit is exceeded. An attacker can send CONTINUATION frames without the END_HEADERS bit, driving CPU consumption of roughly one core per 300 Mbit/s of traffic and causing denial of service. The flaw affects Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8.

Impact

An unauthenticated remote attacker can exhaust CPU resources on the Envoy proxy, degrading or halting service for legitimate traffic. No data confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via HTTP/2 downstream connections; the CVSS vector shows no privileges or user interaction required. Any deployment exposing HTTP/2 to untrusted clients is in scope.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.8781 (99.75th percentile), indicating high predicted exploitation likelihood. References include a patch advisory and CERT/CC note, with no public exploit tag supplied.

What to do

  • Upgrade Envoy to 1.29.3, 1.28.2, 1.27.4, or 1.26.8 as applicable.
  • If immediate upgrade is not possible, disable HTTP/2 for downstream connections as a workaround.
  • Rate-limit or cap HTTP/2 CONTINUATION frames at the edge where feasible.
  • Monitor CPU utilization on Envoy instances and alert on sustained spikes tied to HTTP/2 traffic.

Detection

  • Inspect HTTP/2 traffic for sequences of CONTINUATION frames lacking END_HEADERS, especially from a single client.
  • Alert on abnormal CPU saturation on Envoy proxies correlated with inbound HTTP/2 request volume.
  • Track per-connection HTTP/2 frame counts and flag clients sending excessive CONTINUATION frames.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-30255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2019-9901Envoyproxy envoy vulnerabilityEnvoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access con…EPSS 5.0%9.8CVE-2023-35941Envoyproxy envoy vulnerabilityEnvoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12…EPSS 0.81%9.8CVE-2023-27488Envoyproxy envoy improper input validation vulnerabilityEnvoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …EPSS 0.73%9.8CVE-2022-21654Envoyproxy envoy improper certificate validation vulnerabilityEnvoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings …EPSS 1.1%9.8CVE-2019-18801Envoyproxy envoy out-of-bounds write vulnerabilityAn issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers wh…EPSS 2.5%9.8CVE-2019-18802Envoyproxy envoy vulnerabilityAn issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. …EPSS 2.5%9.1CVE-2024-39305Envoyproxy envoy use after free vulnerabilityEnvoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed mem…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2024-30255), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.