An attacker can create a TCP connection to listeners configured with `continue_on_listener_filters_timeout` true, wait for Envoy hitting the listener timeout and burn 1 core for the worker thread.
Upstream issue: https://github.com/envoyproxy/envoy/security/advisories/GHSA-3xvf-4396-cj46 Upstream Fix: https://github.com/envoyproxy/envoy/commit/c8de199e2971f79cbcbc6b5eadc8c566b28705d1
This issue doesn't affect Envoy versions < 1.12.0.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-18836
External References: https://github.com/envoyproxy/envoy/security/advisories/GHSA-3xvf-4396-cj46