Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the client to send an unlimited number of CONTINUATION frames even after exceeding Envoy's header map limits. This allows an attacker to send a sequence of CONTINUATION frames without the END_HEADERS bit set causing CPU utilization, consuming approximately 1 core per 300Mbit/s of traffic and culminating in denial of service through CPU exhaustion. Users should upgrade to version 1.29.3, 1.28.2, 1.27.4, or 1.26.8 to mitigate the effects of the CONTINUATION flood. As a workaround, disable HTTP/2 protocol for downstream connections.
CVE-2024-30255
Score elevated to 9.0 because EPSS predicts 89% probability of exploitation within the next 30 days (top 0.5% of all CVEs). NVD baseline CVSS 5.3 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 88%
A fix is available — apply it.
- CVSS v3
- 5.3
- EG Score
- 9.0(high)
- EG Risk
- —
- EPSS
- 99.7%
- KEV
- Not listed
Published
April 4, 2024
Last Modified
November 4, 2025
References (7)
- security-advisories@githubhttp://www.openwall.com/lists/oss-security/2024/04/03/16
- security-advisories@githubhttp://www.openwall.com/lists/oss-security/2024/04/05/3
- security-advisories@githubhttps://github.com/envoyproxy/envoy/security/advisories/GHSA-j654-3ccm-vfmm
- af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2024/04/03/16
- af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2024/04/05/3
- af854a3a-2127-422b-91ae-364da2661108https://github.com/envoyproxy/envoy/security/advisories/GHSA-j654-3ccm-vfmm
- af854a3a-2127-422b-91ae-364da2661108https://www.kb.cert.org/vuls/id/421644
Vendor Advisories for CVE-2024-30255(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | openshift-service-mesh/ratelimit-rhel8:2.5.5-3 | 2024-10-07 | redhat |
| redhat | rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.7.16-6 | 2024-07-11 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 3× in last 7d / 16× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-20 17:06 UTCEPSS rescore
- 2026-07-16 17:01 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-14 14:55 UTCOSV refresh
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-08 15:13 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-01 15:05 UTCEPSS rescore
- 2026-06-26 15:39 UTCOSV refresh
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:17 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
Show 21 moreShow fewer
- 2026-06-08 22:07 UTCOSV refresh
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-24 05:10 UTCEG score recompute
- 2026-05-24 05:10 UTCVendor advisory
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCblackmagic2023/Envoy-CPU-Exhaustion-Vulnerability-PoCFirst seen Apr 9, 2024
CVE-2024-30255 This repository contains a proof-of-concept (PoC) Python script to demonstrate the CPU exhaustion vulnerability in Envoy caused by a flood of CONTINUATION frames.
Open source ↗
Frequently asked(5)
What is CVE-2024-30255?
When was CVE-2024-30255 disclosed?
Is CVE-2024-30255 actively exploited?
What is the CVSS score of CVE-2024-30255?
How do I remediate CVE-2024-30255?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-30255
Is Your Infrastructure Affected by CVE-2024-30255?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.