HTTP Bomb (CVE-2026-47774): What Every Envoy User Needs to Know
The HTTP Bomb (CVE-2026-47774) is a high-severity HTTP/2 denial-of-service flaw in Envoy proxy. A single connection can exhaust 32 GB of memory in ~10 seconds. Here is how it works, who is affected, the patched Envoy versions, and how to mitigate it.
Read more