CVE-2020-8659

Executive Summary

CNCF Envoy versions up to 1.13.0 can consume excessive memory when proxying HTTP/1.1 requests or responses that contain many very small (1‑byte) chunks. The high memory usage can lead to resource exhaustion and a denial‑of‑service condition for affected deployments. No CISA KEV listing currently exists.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2020-03-04T21:15:11.340 - Last Modified: 2026-10-02T21:00:25.163

Original Description: CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

"Happiness does not come from having much, but from being attached to little."

— Cheng Yen
Source: NVD