Impact
An Envoy proxy handling HTTP/3 connections can dereference a null transport socket option during the selection of a connection pool. This null pointer dereference is a CWE‑476 flaw that may cause the process to crash or terminate unexpectedly, leading to a denial of service for the services routed through the affected Envoy instance. The vulnerability is triggered when a client initiates an HTTP/3 session that exercises the connection‑pool selection logic, which may provide the attacker a remote execution path to disrupt the proxy.
Affected Systems
The vulnerability affects the Envoy distributed proxy. No specific product version is listed, so any installation that includes the HTTP/3 connection‑pool selection path may be impacted until a fix is released. The vendor information is provided by the Envoy community in this CVE record.
Risk and Exploitability
The CVSS score is 5.9, indicating medium severity. EPSS is not available and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector is a remote client sending an HTTP/3 request to the vulnerable Envoy instance. While the flaw does not provide direct code execution, the resulting crash can interrupt service availability and degrade overall system reliability, especially in high‑availability deployments.
OpenCVE Enrichment