Use-after-free in envoy - CVE-2021-43825

 

Use-after-free in envoy - CVE-2021-43825

Published: February 22, 2022 / Updated: August 26, 2026


Vulnerability identifier: #VU145847
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43825
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to affect integrity and availability of the service.

The vulnerability exists due to use-after-free in response filters when processing responses whose size is increased beyond downstream buffer limits. A remote attacker can trigger response processing with expanded response data to affect integrity and availability of the service.

User interaction is required for exploitation.


Affected software

envoy

How to mitigate CVE-2021-43825

Install security update from vendor's website.

envoy - addressed in versions 1.18.6, 1.19.3, 1.20.2, 1.21.1

External References

Related Security Bulletins