CVE-2021-39162

HIGH

Envoy < 1.18.4 and Pomerium < 0.15.1 - Denial of Service via H/2 GOAWAY and SETTINGS Frame

Title source: llm
STIX 2.1

Description

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.

References (3)

Core 3
Core References
Not Applicable, Third Party Advisory x_refsource_misc
https://groups.google.com/g/envoy-announce/c/5xBpsEZZDfE/m/wD05NZBbAgAJ

Scores

CVSS v3 8.6
EPSS 0.0159
EPSS Percentile 72.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-754
Status published
Products (4)
envoyproxy/envoy 1.19.0
envoyproxy/envoy < 1.18.4
pomerium/pomerium 0.15.0
pomerium/pomerium 0 - 0.15.1Go
Published Sep 09, 2021
Tracked Since Feb 18, 2026