Impact
The vulnerability involves a use‑after‑free condition in the ext_authz component of Envoy Proxy after it rejects an HTTP request. This flaw can cause the process to access freed memory, potentially leading to a crash or, in a worst‑case scenario, arbitrary code execution if the memory is reused maliciously. The impact is primarily denial of service or memory integrity loss rather than immediate remote code execution.
Affected Systems
Envoy Proxy is affected. No specific vendor‑product or version information is provided by the CNA, so all installations using the ext_authz filter are potentially vulnerable until an official fix is applied.
Risk and Exploitability
With a CVSS score of 5.9 the risk is moderate. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, via network traffic that triggers the filter’s rejection logic. Exploitability requires the attacker to send crafted HTTP requests to the proxied service. The lack of an EPSS score suggests low to moderate exploitation probability, but the potential for causing service outages cannot be ignored.
OpenCVE Enrichment