Uncaught Exception in envoy - CVE-2021-28683
Published: April 16, 2021 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of unknown TLS alert codes in the TLS alert processing logic when processing a peer-supplied TLS alert. A remote attacker can send a TLS alert with an unknown code to cause a denial of service.