Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-9900

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 7.5
Products affected by CVE-2019-9900


Contact Us

Shodan ® - All rights reserved