Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23324.json"
}{
"cpe": "cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.26.0"
},
{
"fixed": "1.26.7"
},
{
"introduced": "1.27.0"
},
{
"fixed": "1.27.3"
},
{
"introduced": "1.28.0"
},
{
"fixed": "1.28.1"
},
{
"introduced": "1.29.0"
},
{
"fixed": "1.29.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23324.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"287414039130216666753422066581134153904",
"174352011201520729131336644061757509450",
"283878478509206036206438752474858060194"
],
"threshold": 0.9
},
"id": "CVE-2024-23324-1589f979",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/29989f6cc8bfd8cd2ffcb7c42711eb02c7a5168a",
"target": {
"file": "test/extensions/filters/listener/proxy_protocol/proxy_protocol_test.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "96041769106949552248343524645813715058",
"length": 1869
},
"id": "CVE-2024-23324-27af30ad",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/29989f6cc8bfd8cd2ffcb7c42711eb02c7a5168a",
"target": {
"file": "source/extensions/filters/listener/proxy_protocol/proxy_protocol.cc",
"function": "Filter::parseTlvs"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"190634821861394556500015313664835359860",
"144393821466093071379541029244765152285",
"268145672319149625425849768139433951331",
"48597713298747754895897203892625892373",
"169258724734926006536027940972651439816",
"294063732621406523509811136975097306330",
"34760593104679016273539915781354907948",
"98191952882749236895027930608387012343"
],
"threshold": 0.9
},
"id": "CVE-2024-23324-2ce314af",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/envoyproxy/envoy/commit/29989f6cc8bfd8cd2ffcb7c42711eb02c7a5168a",
"target": {
"file": "source/extensions/filters/listener/proxy_protocol/proxy_protocol.cc"
}
}
]
"2026-08-12T15:15:00Z"