Skip to main content
Vulnerability Database/CVE-2024-34362

CVE-2024-34362: Envoyproxy Envoy Use-After-Free Vulnerability

CVE-2024-34362 is a use-after-free vulnerability in Envoyproxy Envoy that allows attackers to crash the proxy by exploiting HttpConnectionManager with EnvoyQuicServerStream. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-34362 Overview

CVE-2024-34362 is a use-after-free vulnerability [CWE-416] in Envoy, a cloud-native open source edge and service proxy. The flaw exists in the HttpConnectionManager (HCM) component when interacting with EnvoyQuicServerStream. A remote attacker can trigger the condition by sending a request without a FIN flag, followed by a RESET_STREAM frame, and then closing the connection after receiving the response. Successful exploitation crashes the Envoy process, resulting in denial of service for all traffic routed through the affected proxy.

Critical Impact

Unauthenticated remote attackers can crash Envoy proxies handling HTTP/3 (QUIC) traffic, disrupting availability for downstream services.

Affected Products

  • Envoyproxy Envoy (multiple versions prior to fixed releases)
  • Deployments using HttpConnectionManager with QUIC/HTTP3 listeners
  • Service meshes and API gateways built on affected Envoy versions

Discovery Timeline

  • 2024-06-04 - CVE-2024-34362 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-34362

Vulnerability Analysis

The vulnerability resides in Envoy's HttpConnectionManager filter when paired with the QUIC server stream implementation, EnvoyQuicServerStream. Envoy retains a reference to stream state that is freed before all code paths finish using it, meeting the classic definition of a use-after-free [CWE-416]. When the freed memory is subsequently accessed, the process terminates.

The attack requires network access to a QUIC (HTTP/3) listener but no authentication or user interaction. High attack complexity reflects the specific sequence of frames needed to win the race between response delivery and connection teardown. Impact is limited to availability; there is no direct compromise of confidentiality or integrity.

Root Cause

The root cause is improper lifetime management between the HCM stream object and the underlying QUIC server stream. Envoy processes a RESET_STREAM frame and later a connection close while HCM still holds a pointer to stream-associated memory that has been released. Accessing the dangling reference produces a crash.

Attack Vector

An attacker sends an HTTP/3 request without setting the FIN bit, keeping the stream open. The attacker then transmits a RESET_STREAM frame to abort the request. After Envoy returns a response, the attacker closes the QUIC connection. The ordering of these events triggers the freed-memory access inside HCM and terminates the Envoy worker process. Repeated requests can produce sustained denial of service. See the GitHub Security Advisory for technical details on the affected code paths.

Detection Methods for CVE-2024-34362

Indicators of Compromise

  • Unexpected Envoy worker process crashes or restarts logged by the supervisor or container runtime
  • QUIC/HTTP3 streams closed with RESET_STREAM followed by immediate connection close from the same peer
  • Spikes in HTTP/3 connection resets on ingress listeners without corresponding client-side errors
  • Envoy admin /stats counters showing increases in downstream_cx_destroy and QUIC reset events

Detection Strategies

  • Correlate Envoy access logs with process crash events to identify request patterns preceding each restart
  • Alert on repeated RESET_STREAM frames from single source IPs targeting HTTP/3 listeners
  • Deploy network telemetry that flags QUIC streams opened without FIN and terminated by reset within short windows

Monitoring Recommendations

  • Track Envoy process uptime and restart frequency across all mesh instances
  • Ingest Envoy stats and QUIC connection telemetry into a centralized analytics platform for anomaly detection
  • Monitor upstream service availability metrics for correlated failures caused by proxy restarts

How to Mitigate CVE-2024-34362

Immediate Actions Required

  • Upgrade Envoy to a patched release listed in the GitHub Security Advisory GHSA-hww5-43gv-35jv
  • Inventory all Envoy deployments, including service meshes such as Istio and API gateways, and identify those exposing HTTP/3 listeners
  • Restrict exposure of QUIC listeners to trusted networks until patches are applied

Patch Information

Envoy maintainers released fixed versions addressing the use-after-free. Refer to the Envoy security advisory for the exact patched version numbers corresponding to each supported release branch. Redeploy service mesh control planes and sidecars after upgrading.

Workarounds

  • Disable HTTP/3 (QUIC) listeners on Envoy proxies if immediate patching is not feasible
  • Terminate HTTP/3 at an upstream load balancer or CDN that is not affected, and forward HTTP/1.1 or HTTP/2 to Envoy
  • Apply rate limiting to QUIC connections to reduce the impact of repeated crash attempts
bash
# Example: disable HTTP/3 by removing the QUIC listener transport socket
# and serving only HTTP/2 over TLS until Envoy is upgraded
listeners:
  - name: listener_https
    address:
      socket_address: { address: 0.0.0.0, port_value: 443 }
    # udp_listener_config removed to disable QUIC
    filter_chains:
      - filters:
          - name: envoy.filters.network.http_connection_manager
            typed_config:
              codec_type: HTTP2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.