[WID-SEC-2026-2127] Google Cloud Service Mesh und Envoy Proxy: Schwachstelle ermöglicht Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 29.06.2026 Stand 30.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Produktbeschreibung Google Cloud Platform (GCP) ist eine Sammlung von Cloud-Computing-Diensten von Google, die Infrastruktur, Datenanalyse, maschinelles Lernen und Entwicklungstools bietet. Unternehmen können dadurch Anwendungen in der Cloud zu aufbauen und skalierbar bereitzustellen. Produkte 29.06.2026 Google Cloud Platform Envoy Proxy Google Cloud Platform in-cluster Cloud Service Mesh <1.29.5-asm.5 Google Cloud Platform in-cluster Cloud Service Mesh <1.28.9-asm.4 Google Cloud Platform in-cluster Cloud Service Mesh <1.27.9-asm.9 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Google Cloud Service Mesh und Envoy Proxy ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A remote, anonymous attacker can exploit a vulnerability in Google Cloud Service Mesh and Envoy Proxy to cause a Denial of Service. The vulnerability has a CVSS base score of 7.5 (High) and affects Google Cloud Platform in-cluster Cloud Service Mesh versions earlier than 1.29.5-asm.5, 1.28.9-asm.4, and 1.27.9-asm.9. A mitigation is available, but the article does not specify a patched version or a detailed workaround.