CVE-2016-5385: Httpoxy Vulnerability
Incident Report for amazee.io
Resolved
The patch is rolled out to all servers. There where a few downtimes of a couple of seconds for some sites. At this point every site hosted on amazee.io is completely secure against HTTPoxie / CVE-2016-5385. We suggest to update your Drupal 8 sites to version 8.1.7.
Posted Jul 18, 2016 - 15:32 UTC
Identified
We're currently rolling out a patch which mitigates the vulnerability. During the rollout minor downtimes can occur. Our engineers are monitoring the rollout closely.
Posted Jul 18, 2016 - 14:39 UTC
Update
Within CVE-2016-5385 for PHP there's a new Issue with unchecked HTTP Fields which have an impact on several libraries used. For Drupal 8 this affects Guzzle which released a patch already : https://github.com/guzzle/guzzle/releases/tag/6.2.1.

We're currently rolling out mitigation actions against this vulnerability.
Posted Jul 18, 2016 - 14:34 UTC
Investigating
We are currently investigating this issue.
Posted Jul 18, 2016 - 14:32 UTC