Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with auto_sni enabled, a request containing a host/:authority header longer than 255 characters triggers an abnormal termination of Envoy process. Envoy does not gracefully handle an error when setting SNI for outbound TLS connection. The error can occur when Envoy attempts to use the host/:authority header value longer than 255 characters as SNI for outbound TLS connection. SNI length is limited to 255 characters per the standard. Envoy always expects this operation to succeed and abnormally aborts the process when it fails. This vulnerability is fixed in 1.30.1, 1.29.4, 1.28.3, and 1.27.5.
{
"cwe_ids": [
"CWE-253",
"CWE-617"
],
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "11.30.1"
},
{
"introduced": "1.29.0"
},
{
"fixed": "1.29.4"
},
{
"introduced": "1.28.0"
},
{
"fixed": "1.28.3"
},
{
"introduced": "1.13.0"
},
{
"fixed": "1.27.5"
}
]
}
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32475.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32475.json"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"196265363333543913368690057492178668256",
"219184164543942712087488099433001400895",
"231247354412352955568999083979159396895",
"208168687639638768195061490223100863466",
"136005117763504893098256484638948698229",
"19955777087609349659207348313230992773",
"197290446457669134741538745570821555079",
"282394982518183695106282222756784491793",
"94559485442665205621354591321081355508",
"63507542503873142697714897041297722992",
"11607385698390987861458315860881662684",
"314688785246493963613919604961071038850",
"116571994878666957163255698740826551755",
"301802991708189260725358485947034710757",
"30817131239164096896226204789433015331",
"20130423877109515326560335076211633599"
],
"threshold": 0.9
},
"target": {
"file": "source/common/tls/context_impl.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-0e589612",
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "89239873660566626255438729488444718795",
"length": 505.0
},
"target": {
"function": "SslSocket::SslSocket",
"file": "source/common/tls/ssl_socket.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-474ceeaf",
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"123710286548140867443267761244278305224",
"252216056405913497585633295190284520454",
"179383444662765901029988137414766364016"
],
"threshold": 0.9
},
"target": {
"file": "test/extensions/filters/http/dynamic_forward_proxy/proxy_filter_integration_test.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-55b12d25",
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"194730531760642834296261184502271781456",
"90739946565669074811734476015115961749",
"39404860188519564340611459069522318026",
"2339588023847146527697150212909840046",
"205082615803891289847865662191036443631",
"51855934738868422792965969321287271802",
"121187654154240361771167675095748622198",
"336818603243513249170331339585647582707",
"238571029998112481326622032474278349592",
"198748899008268399324071209129022253255"
],
"threshold": 0.9
},
"target": {
"file": "source/common/tls/ssl_socket.h"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-5b7e67f9",
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "82164648954616274089818015603251897791",
"length": 185.0
},
"target": {
"function": "ContextImpl::newSsl",
"file": "source/common/tls/context_impl.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-70b284e7",
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "219647051739277534396867028264106491323",
"length": 1500.0
},
"target": {
"function": "ClientContextImpl::newSsl",
"file": "source/common/tls/context_impl.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-a7d8b8db",
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "117392380062933651402478859462417783430",
"length": 468.0
},
"target": {
"function": "ClientSslSocketFactory::createTransportSocket",
"file": "source/common/tls/ssl_socket.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-b39a14d2",
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"122654754231967532761253556156357179309",
"104900939735403072843069886003311315212",
"178037668096777109412317791497924504868",
"113418175396272240939642745217645535454",
"153567590179389659689710715878459735658",
"244063126830949209008618193026192990062",
"198399593299022782831409680588297605316",
"194603727378317274401766142200850891293",
"104679443199176205420789649908765332672",
"178231157198177473542182096787203090196",
"265059630392916847648697800745160827147",
"273083707954027243630530114724660075623",
"84743113509875915803323015157367815656",
"38036879578051094614028454264184277132",
"236425614214190300891015058429465881435",
"240832190028766427807996197769130094495",
"68817266063356521254052267622956181254",
"143303374608939754136848376336028387006",
"69045853875795090318939745146395019149",
"260924732035224019725539400161898658817",
"138409318944008911764813133972045876393",
"193345671876304345857748803186560054727",
"285932142411494883344856773497301781217",
"242127570792598478690745888602681319533",
"323672252593245754630561413833396554934",
"278003859223407658857602639832410534814",
"197777993997850869122429664666326398276",
"96701026663861027761047542696178796995",
"158814633065638241320036178083522730533",
"245963602516233488556716950818241189127",
"3633459932220702307907136321925237506",
"234492468008824426036472014171249234400",
"301669121292967509628765777161908604776",
"337288315604816648376774562543384906355",
"272617699068473666051362115990977544805"
],
"threshold": 0.9
},
"target": {
"file": "source/common/tls/ssl_socket.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-cee41281",
"signature_type": "Line"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "296451427430358962930393798602868197843",
"length": 462.0
},
"target": {
"function": "ServerSslSocketFactory::createDownstreamTransportSocket",
"file": "source/common/tls/ssl_socket.cc"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-e0755ebf",
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"152151580128973545135838659822840147134",
"267171159884167873910256461198894895936",
"301362874245753853588894718391018553843",
"285165470332324947811557217532155392521",
"179247545719528175893683190296469912463",
"314841467098112626473165011854778063693",
"259721735050968467728188516630729019108",
"80227059533105405900081762837934544589"
],
"threshold": 0.9
},
"target": {
"file": "source/common/tls/context_impl.h"
},
"source": "https://github.com/envoyproxy/envoy/commit/b47fc6648d7c2dfe0093a601d44cb704b7bad382",
"id": "CVE-2024-32475-f472c873",
"signature_type": "Line"
}
]
"2026-08-05T08:17:10Z"