{"id":"CVE-2024-32475","summary":"Envoy RELEASE_ASSERT using auto_sni with :authority header \u003e 255 bytes","details":"Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process. Envoy does not gracefully handle an error when setting SNI for outbound TLS connection. The error can occur when Envoy attempts to use the `host`/`:authority` header value longer than 255 characters as SNI for outbound TLS connection. SNI length is limited to 255 characters per the standard. Envoy always expects this operation to succeed and abnormally aborts the process when it fails. This vulnerability is fixed in 1.30.1, 1.29.4, 1.28.3, and 1.27.5.\n","aliases":["BIT-envoy-2024-32475","GHSA-3mh5-6q8v-25wj"],"modified":"2026-08-12T15:15:58.889427Z","published":"2024-04-18T14:18:18.947Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-253","CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32475.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.30.0"},{"fixed":"11.30.1"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32475.json"},{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-3mh5-6q8v-25wj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32475"},{"type":"FIX","url":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"bb7ceff4c3c5bd4555dff28b6e56d27f2f8be0a7"},{"fixed":"be4f1cfd31c79fc05651efa2f88429b3c03d1d9e"},{"introduced":"b5ca88acee3453c9459474b8f22215796eff4dde"},{"fixed":"a6bded6ebcd6ba479414dd2dd47e73c18d15708e"},{"introduced":"a6d1d66a62b985baed414ba90ad0daebfc074664"},{"fixed":"8eef22b927682e9ff6f59cf9f26e440b41219fe6"},{"introduced":"50ea83e602d5da162df89fd5798301e22f5540cf"},{"fixed":"b47fc6648d7c2dfe0093a601d44cb704b7bad382"}],"database_specific":{"cpe":["cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","cpe:2.3:a:envoyproxy:envoy:1.30.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.13.0"},{"fixed":"1.27.5"},{"introduced":"1.28.0"},{"fixed":"1.28.3"},{"introduced":"1.29.0"},{"fixed":"1.29.4"},{"introduced":"1.30.0"},{"last_affected":"1.30.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["1.30.0","v1.30.0","v1.27.4","v1.28.2","v1.29.3","v1.29.2","v1.29.1","v1.28.1","v1.27.3","v1.29.0","v1.28.0","v1.27.2","v1.27.1","v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.0","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.18.2","v1.18.1","v1.18.0","v1.17.0","v1.16.0","v1.15.0","v1.14.0","v1.13.0"],"database_specific":{"vanir_signatures":[{"id":"CVE-2024-32475-0e589612","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/context_impl.cc"},"deprecated":false,"digest":{"line_hashes":["196265363333543913368690057492178668256","219184164543942712087488099433001400895","231247354412352955568999083979159396895","208168687639638768195061490223100863466","136005117763504893098256484638948698229","19955777087609349659207348313230992773","197290446457669134741538745570821555079","282394982518183695106282222756784491793","94559485442665205621354591321081355508","63507542503873142697714897041297722992","11607385698390987861458315860881662684","314688785246493963613919604961071038850","116571994878666957163255698740826551755","301802991708189260725358485947034710757","30817131239164096896226204789433015331","20130423877109515326560335076211633599"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/ssl_socket.cc","function":"SslSocket::SslSocket"},"deprecated":false,"digest":{"function_hash":"89239873660566626255438729488444718795","length":505},"id":"CVE-2024-32475-474ceeaf","signature_type":"Function"},{"id":"CVE-2024-32475-55b12d25","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"test/extensions/filters/http/dynamic_forward_proxy/proxy_filter_integration_test.cc"},"deprecated":false,"digest":{"line_hashes":["123710286548140867443267761244278305224","252216056405913497585633295190284520454","179383444662765901029988137414766364016"],"threshold":0.9}},{"id":"CVE-2024-32475-5b7e67f9","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/ssl_socket.h"},"deprecated":false,"digest":{"line_hashes":["194730531760642834296261184502271781456","90739946565669074811734476015115961749","39404860188519564340611459069522318026","2339588023847146527697150212909840046","205082615803891289847865662191036443631","51855934738868422792965969321287271802","121187654154240361771167675095748622198","336818603243513249170331339585647582707","238571029998112481326622032474278349592","198748899008268399324071209129022253255"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"82164648954616274089818015603251897791","length":185},"id":"CVE-2024-32475-70b284e7","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/context_impl.cc","function":"ContextImpl::newSsl"}},{"deprecated":false,"digest":{"function_hash":"219647051739277534396867028264106491323","length":1500},"id":"CVE-2024-32475-a7d8b8db","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/context_impl.cc","function":"ClientContextImpl::newSsl"}},{"deprecated":false,"digest":{"function_hash":"117392380062933651402478859462417783430","length":468},"id":"CVE-2024-32475-b39a14d2","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/ssl_socket.cc","function":"ClientSslSocketFactory::createTransportSocket"}},{"source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/ssl_socket.cc"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["122654754231967532761253556156357179309","104900939735403072843069886003311315212","178037668096777109412317791497924504868","113418175396272240939642745217645535454","153567590179389659689710715878459735658","244063126830949209008618193026192990062","198399593299022782831409680588297605316","194603727378317274401766142200850891293","104679443199176205420789649908765332672","178231157198177473542182096787203090196","265059630392916847648697800745160827147","273083707954027243630530114724660075623","84743113509875915803323015157367815656","38036879578051094614028454264184277132","236425614214190300891015058429465881435","240832190028766427807996197769130094495","68817266063356521254052267622956181254","143303374608939754136848376336028387006","69045853875795090318939745146395019149","260924732035224019725539400161898658817","138409318944008911764813133972045876393","193345671876304345857748803186560054727","285932142411494883344856773497301781217","242127570792598478690745888602681319533","323672252593245754630561413833396554934","278003859223407658857602639832410534814","197777993997850869122429664666326398276","96701026663861027761047542696178796995","158814633065638241320036178083522730533","245963602516233488556716950818241189127","3633459932220702307907136321925237506","234492468008824426036472014171249234400","301669121292967509628765777161908604776","337288315604816648376774562543384906355","272617699068473666051362115990977544805"]},"id":"CVE-2024-32475-cee41281","signature_type":"Line","signature_version":"v1"},{"digest":{"function_hash":"296451427430358962930393798602868197843","length":462},"id":"CVE-2024-32475-e0755ebf","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/ssl_socket.cc","function":"ServerSslSocketFactory::createDownstreamTransportSocket"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382","target":{"file":"source/common/tls/context_impl.h"},"deprecated":false,"digest":{"line_hashes":["152151580128973545135838659822840147134","267171159884167873910256461198894895936","301362874245753853588894718391018553843","285165470332324947811557217532155392521","179247545719528175893683190296469912463","314841467098112626473165011854778063693","259721735050968467728188516630729019108","80227059533105405900081762837934544589"],"threshold":0.9},"id":"CVE-2024-32475-f472c873","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32475.json","vanir_signatures_modified":"2026-08-12T15:15:58Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}