CVE-2020-8661
NixOS vulnerability analysis and mitigation

Overview

CNCF Envoy through version 1.13.0 contains a vulnerability where the system may consume excessive amounts of memory when responding internally to pipelined requests. The vulnerability was discovered by Alyssa Wilk from Google LLC and was assigned CVE-2020-8661. The issue affects the HTTP/1 codec component of Envoy (GitHub Advisory).

Technical details

The vulnerability occurs when Envoy sends internally generated 400 error responses to illegally formed requests, which are sent to the Network::Connection buffer. If a client reads these responses slowly, it can lead to accumulation of a large number of responses and unlimited memory consumption. This issue bypasses Envoy's overload manager, which itself sends internally generated responses when approaching configured memory thresholds, thereby exacerbating the problem. The vulnerability has been assigned a CVSS v3 Score of 7.5, indicating a Moderate impact (Red Hat CVE).

Impact

The primary impact of this vulnerability is potential denial-of-service and excessive resource consumption, particularly memory. When exploited, it can lead to functionally unlimited memory consumption in the affected system, potentially causing service disruption (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Envoy versions 1.13.1 and 1.12.3. Users are advised to upgrade to these or later versions to address the issue. The fix includes implementation of HTTP/1.1 flood protection, which can be temporarily disabled using the runtime feature envoy.reloadable_features.http1_flood_protection (Envoy Docs).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management