envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0 취약점
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM termination of the Envoy process and denial of service. The issue arises from the combination of two behaviors. First, cookie header bytes are not fully accounted for during request header size validation in Envoy. Second, HPACK header block limits in oghttp2/quiche are enforced o...
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM termination of the Envoy process and denial of service. The issue arises from the combination of two behaviors. First, cookie header bytes are not fully accounted for during request header size validation in Envoy. Second, HPACK header block limits in oghttp2/quiche are enforced o...
영향 제품·버전
제품 envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0
영향 버전 envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0 >= < 1.35.11, >= >= 1.36.0, < 1.36.7, >= >= 1.37.0, < 1.37.3, >= >= 1.38.0, < 1.38.1, < 1.35.11, >= 1.36.0 < 1.36.7, >= 1.37.0 < 1.37.3, 1.38.0, >= 2.6 < 2.6.17, >= 3.0 < 3.0.12, >= 3.1 < 3.1.9, >= 3.2 < 3.2.6, >= 3.3 < 3.3.4
수정 버전 envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0 1.35.11, 1.36.7, 1.37.3, 2.6.17, 3.0.12, 3.1.9, 3.2.6, 3.3.4
envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0의 현재 전체 버전이 공식 영향 범위(envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0 >= < 1.35.11, >= >= 1.36.0, < 1.36.7, >= >= 1.37.0, < 1.37.3, >= >= 1.38.0, < 1.38.1, < 1.35.11, >= 1.36.0 < 1.36.7, >= 1.37.0 < 1.37.3, 1.38.0, >= 2.6 < 2.6.17, >= 3.0 < 3.0.12, >= 3.1 < 3.1.9, >= 3.2 < 3.2.6, >= 3.3 < 3.3.4)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
저장소 Security Advisory 원문에서 CVE 번호가 CVE-2026-47774와 일치하는지 먼저 확인하고, 일치할 때만 수정 버전 값(1.35.11, 1.36.7, 1.37.3, 2.6.17, 3.0.12, 3.1.9, 3.2.6, 3.3.4)을 조치 기준으로 사용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 envoyproxy envoy, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0 1.35.11, 1.36.7, 1.37.3, 2.6.17, 3.0.12, 3.1.9, 3.2.6, 3.3.4 기준을 충족하는지 확인합니다. 이어서 서비스 거부(DoS) 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.