Impact
A use‑after‑free flaw has been identified in Envoy’s HTTP/3 handling of late datagrams. This weakness, classified as CWE‑416, may allow an attacker to trigger undefined behavior that could be leveraged to execute arbitrary code on the affected system. The exact impact depends on the system state and the attacker’s ability to send crafted HTTP/3 traffic, but the nature of a use‑after‑free indicates potential critical compromise.
Affected Systems
The vulnerability targets Envoy’s HTTP/3 implementation; specific product versions are not listed in the available data. The flaw exists wherever Envoy processes late UDP datagrams for HTTP/3 connections.
Risk and Exploitability
With a CVSS score of 7.5, the flaw is considered high severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote over the network, where a malicious actor sends specially crafted HTTP/3 packets to an Envoy instance that can trigger the vulnerable code path.
OpenCVE Enrichment