← Back to CVE List

CVE-2019-9900

Published: 2019-04-25T15:29Z
Last Modified: 2024-11-21T04:52Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt