Vulnerabilities > Projectcontour > Contour > 1.15.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2021-07-23 CVE-2021-32783 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Projectcontour Contour
Contour is a Kubernetes ingress controller using Envoy proxy.
network
low complexity
projectcontour CWE-610
5.5