CVE-2024-45808: exploitation status and patch state

CVE-2024-45808 · CVSS 6.5 MEDIUM · EPSS <1%

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for the `REQUESTED_SERVER_NAME` field for access loggers. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Is CVE-2024-45808 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2024-45808

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.