Description
Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.
Published: 2024-06-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-34736 Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00012}

epss

{'score': 0.0001}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 7e-05}

epss

{'score': 0.00012}


Subscriptions

Envoyproxy Envoy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:51:11.160Z

Reserved: 2024-05-02T06:36:32.439Z

Link: CVE-2024-34363

cve-icon Vulnrichment

Updated: 2024-08-02T02:51:11.160Z

cve-icon NVD

Status : Modified

Published: 2024-06-04T21:15:34.743

Modified: 2024-11-21T09:18:30.680

Link: CVE-2024-34363

cve-icon Redhat

Severity : Important

Publid Date: 2024-06-04T00:00:00Z

Links: CVE-2024-34363 - Bugzilla

cve-icon OpenCVE Enrichment

No data.