CVE-2024-23323
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-23323 affects Envoy, a high-performance edge/middle/service proxy. The vulnerability was discovered and disclosed in February 2024, where a regex expression compilation issue was identified in the URI template matcher functionality. The vulnerability affects multiple versions of Envoy including versions prior to 1.29.1, 1.28.1, 1.27.3, and 1.26.7 (GitHub Advisory, NVD).

Technical details

The vulnerability stems from a design flaw where the regex expression is compiled for every request when using the regex URL template matcher. This implementation leads to inefficient CPU computation and resource consumption. The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (MEDIUM) by NIST and 4.3 (MEDIUM) by GitHub, with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L. The weakness has been categorized under CWE-400 (Uncontrolled Resource Consumption) and CWE-1176 (Inefficient CPU Computation) (NVD).

Impact

The primary impact of this vulnerability is potential Denial of Service (DoS) through CPU exhaustion. When multiple routes are configured with regex matchers, the continuous compilation of regex expressions for every request can result in high CPU usage and increased request latency, potentially affecting service availability (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been addressed in Envoy versions 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade to these patched versions. There are no known workarounds for this vulnerability (NVD).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management