Use-after-free in envoy - CVE-2021-43825
Published: February 22, 2022 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to affect integrity and availability of the service.
The vulnerability exists due to use-after-free in response filters when processing responses whose size is increased beyond downstream buffer limits. A remote attacker can trigger response processing with expanded response data to affect integrity and availability of the service.
User interaction is required for exploitation.