QID 981065

QID 981065: Go (go) Security Update for github.com/pomerium/pomerium (GHSA-5wjf-62hw-q78r)

Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset.

This can result in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.Workaround:
    N/A
    Vendor References

    CVEs related to QID 981065

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5wjf-62hw-q78r github.com/pomerium/pomerium URL Logo github.com/advisories/GHSA-5wjf-62hw-q78r