Use-after-free in envoy - CVE-2021-43826
Published: February 22, 2022 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to affect integrity and availability.
The vulnerability exists due to use-after-free in the TCP-over-HTTP tunneling functionality when handling a downstream disconnect during upstream connection establishment. A remote attacker can trigger a downstream disconnect condition to affect integrity and availability.
User interaction is required.