Lucene search

K
osvGoogleOSV:CVE-2021-43826
HistoryFeb 22, 2022 - 11:15 p.m.

CVE-2021-43826

2022-02-2223:15:00
Google
osv.dev
16
envoy
open source
proxy
crash
upstream tunneling
cloud-native
applications
cve-2021-43826

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

40.1%

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config> and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

40.1%