Security Advisory

CVE-2021-43826

7.5
HIGH

Vulnerability Description

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling ` and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.
Published Date February 22, 2022
Official Source NIST NVD Advisory