Lucene search

K
osvGoogleOSV:CVE-2019-15225
HistoryAug 19, 2019 - 11:15 p.m.

CVE-2019-15225

2019-08-1923:15:10
Google
osv.dev
6

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

72.0%

In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to result in a denial of service (memory consumption). This is a related issue to CVE-2019-14993.

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

72.0%