CVE-2020-12605: Envoyproxy Envoy
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.
Affected products
- Envoyproxy Envoy: up to and including 1.12.4; version 1.13.2 only; version 1.14.2 only
Published 2020-07-01. Last modified 2026-06-17.