Fedora Account System
Red Hat Associate
Red Hat Customer
Cross-user response poisoning involving generic, non-WebSocket HTTP upgrades. Request payload sent before an upstream accepted the upgrade could be interpreted as a pipelined request and leave a contaminated connection in the shared upstream pool. Envoy now pauses the payload until the upgrade is accepted and prevents rejected connections from being reused. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5) Embargoed until 2026-08-26 13:00 GMT per Envoy upstream disclosure. PSIRTSUPT-21132.