{"id":"CVE-2024-53271","summary":"HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy","details":"Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy  does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["BIT-envoy-2024-53271","GHSA-rmm5-h2wv-mg4f"],"modified":"2026-08-12T15:16:06.787058Z","published":"2024-12-18T19:12:20.612Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-670"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53271.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53271.json"},{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-rmm5-h2wv-mg4f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53271"},{"type":"FIX","url":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"7b8baff1758f0a584dcc3cb657b5032000bcb3d7"},{"fixed":"688c4bbe47f4d05bb8ed268f5172bb026cf03242"},{"introduced":"86dc7ef91ca15fb4957a74bd599397413fc26a24"},{"fixed":"da56f6da63079baecef9183436ee5f4141a59af8"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.31.0"},{"fixed":"1.31.5"},{"introduced":"1.32.0"},{"last_affected":"1.32.3"}]}}],"versions":["v1.31.4","v1.31.3","v1.32.0","v1.31.2","v1.31.1","v1.31.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53271.json","vanir_signatures_modified":"2026-08-12T15:16:06Z","vanir_signatures":[{"digest":{"line_hashes":["103798657930766994121874004576930631224","331523682770753191470734475458021926338","11773481280393553357145394575631605302","11609851629032317194919953429748751707"],"threshold":0.9},"id":"CVE-2024-53271-112d3db4","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8","target":{"file":"source/common/http/http1/balsa_parser.h"},"deprecated":false},{"source":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8","target":{"file":"source/common/runtime/runtime_features.cc"},"deprecated":false,"digest":{"line_hashes":["172110461990506785251396894379179802222","330238127323719945461772147279773171981","19744423913766154525423811245841517373","168821582513243416232567983687962588807"],"threshold":0.9},"id":"CVE-2024-53271-59710b78","signature_type":"Line","signature_version":"v1"},{"digest":{"function_hash":"242810136237383737051762371201551881794","length":259},"id":"CVE-2024-53271-b3883aa0","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8","target":{"file":"source/common/http/http1/balsa_parser.cc","function":"BalsaParser::MessageDone"},"deprecated":false},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["289119855628334511607348797400759512364","26869864842251686266975916715875066355","161489464626501027959629448820653560201","159600329192064873396702671007197199"]},"id":"CVE-2024-53271-b70e0c13","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8","target":{"file":"source/common/http/http1/balsa_parser.cc"}},{"id":"CVE-2024-53271-d0bb3f29","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/da56f6da63079baecef9183436ee5f4141a59af8","target":{"file":"test/integration/protocol_integration_test.cc"},"deprecated":false,"digest":{"line_hashes":["192494085373027372906483982059308603206","79993336495383740210575267695115962252","192864923389944950845684140415028603237"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"}]}