[Zero Day] Zero day announcement for Envoy users

26 views
Skip to first unread message

Kateryna Nezdolii

unread,
Jun 4, 2026, 5:22:31 AM (2 days ago) Jun 4
to envoy...@googlegroups.com, envoy-dev, envoy-a...@googlegroups.com

Hello Envoy Users,


We would like to inform you that CVE-2026-47774, a memory-exhaustion vulnerability involving a cookie header size-limit bypass and HPACK amplification, is now public following the zero-day disclosure published here:

 https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb

We are currently preparing public releases to mitigate this vulnerability. We expect these releases to be available by the end of the day on June 4, 2026, CEST. We will send a further notification once the releases have been published.


Kind regards,
nezdolik (on behalf of Envoy security team and maintainers)
Reply all
Reply to author
Forward
0 new messages