Vulnerability record · CVE-2024-30255 · published 4 April 2024
CVE-2024-30255: Envoy HTTP/2 CONTINUATION frame flood causes CPU exhaustion
Envoyproxy · Envoy
Envoy's HTTP/2 codec accepts an unlimited number of CONTINUATION frames even after the header map limit is exceeded. An attacker can send CONTINUATION frames without the END_HEADERS bit, driving CPU consumption of roughly one core per 300 Mbit/s of traffic and causing denial of service. The flaw affects Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8.
Description
Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the client to send an unlimited number of CONTINUATION frames even after exceeding Envoy's header map limits. This allows an attacker to send a sequence of CONTINUATION frames without the END_HEADERS bit set causing CPU utilization, consuming approximately 1 core per 300Mbit/s of traffic and culminating in denial of service through CPU exhaustion. Users should upgrade to version 1.29.3, 1.28.2, 1.27.4, or 1.26.8 to mitigate the effects of the CONTINUATION flood. As a workaround, disable HTTP/2 protocol for downstream connections.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated CPU exhaustion with a high EPSS score and a patch available, though not known to be actively exploited.
What it is
Envoy's HTTP/2 codec accepts an unlimited number of CONTINUATION frames even after the header map limit is exceeded. An attacker can send CONTINUATION frames without the END_HEADERS bit, driving CPU consumption of roughly one core per 300 Mbit/s of traffic and causing denial of service. The flaw affects Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8.
Impact
An unauthenticated remote attacker can exhaust CPU resources on the Envoy proxy, degrading or halting service for legitimate traffic. No data confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via HTTP/2 downstream connections; the CVSS vector shows no privileges or user interaction required. Any deployment exposing HTTP/2 to untrusted clients is in scope.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.8781 (99.75th percentile), indicating high predicted exploitation likelihood. References include a patch advisory and CERT/CC note, with no public exploit tag supplied.
What to do
- Upgrade Envoy to 1.29.3, 1.28.2, 1.27.4, or 1.26.8 as applicable.
- If immediate upgrade is not possible, disable HTTP/2 for downstream connections as a workaround.
- Rate-limit or cap HTTP/2 CONTINUATION frames at the edge where feasible.
- Monitor CPU utilization on Envoy instances and alert on sustained spikes tied to HTTP/2 traffic.
Detection
- Inspect HTTP/2 traffic for sequences of CONTINUATION frames lacking END_HEADERS, especially from a single client.
- Alert on abnormal CPU saturation on Envoy proxies correlated with inbound HTTP/2 request volume.
- Track per-connection HTTP/2 frame counts and flag clients sending excessive CONTINUATION frames.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/04/03/16 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/04/05/3 | Mailing List |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-j654-3ccm-vfmm | PatchThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/04/03/16 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/04/05/3 | Mailing List |
| https://github.com/envoyproxy/envoy/security/advisories/GHSA-j654-3ccm-vfmm | PatchThird Party Advisory |
| https://www.kb.cert.org/vuls/id/421644 |
Track CVE-2024-30255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-30255), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.