CVE-2024-34364
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-34364 affects Envoy, a cloud-native, open source edge and service proxy. The vulnerability was discovered and disclosed in June 2024, exposing an out-of-memory (OOM) vector from the mirror response, as the async HTTP client buffers the response with an unbounded buffer. The affected versions include Envoy versions up to 1.27.6, 1.28.0-1.28.4, 1.29.0-1.29.5, and 1.30.0-1.30.2 (NVD).

Technical details

The vulnerability stems from the async HTTP client's behavior of fully buffering mirror response messages in memory without bounds. This implementation flaw allows potential exploitation when a mirror cluster sends extremely large response messages. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) by NIST and 5.7 (Medium) by GitHub, with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H. The issue affects multiple components including wasm filter, lua filter, ext_proc, oauth filter, ext_authz, jwks_fetcher, and various other Envoy components (GitHub Advisory).

Impact

The primary impact of this vulnerability is a potential denial of service condition where Envoy instances can be forced into an out-of-memory state. This occurs when a malicious backend sends extremely large responses, leading to unbounded memory consumption and eventual service disruption (GitHub Advisory).

Exploitability

The vulnerability requires network access and low privileges but does need user interaction for exploitation. Most auth/log related extensions assume trusted upstream, while components like wasm, lua, and ext_proc may not assume it, making them potentially more susceptible to exploitation (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 1.30.2, 1.29.5, 1.28.4, and 1.27.6. The fix includes disabling buffering of mirror responses and implementing a configurable hard limit for the HTTP async client. Users can set this limit through a runtime key based on their specific needs and security requirements (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management