NULL pointer dereference in envoy - CVE-2021-43824
Published: February 22, 2022 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the JWT filter safe_regex match functionality when processing crafted input. A remote attacker can trigger the vulnerable code path to cause a denial of service.
User interaction is required to process the crafted input.