NULL pointer dereference in envoy - #VU153340
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the OAuth2 HTTP filter when processing a path-less HTTP CONNECT request. A remote attacker can send a path-less HTTP CONNECT request to cause a denial of service.
Exploitation requires reaching a listener whose HTTP filter chain includes the OAuth2 filter.