Impact
The vulnerability is a heap use‑after‑free triggered by HTTP/2 trailers that do not include END_STREAM in Envoy’s oghttp2 implementation. This flaw may lead to memory corruption, potentially causing crashes or unintended behavior in the affected service.
Affected Systems
The affected product is the Envoy proxy, a widely used open‑source HTTP/2 load balancer and service proxy. Specific affected releases are not listed in the provided data, so users should verify whether their current Envoy version is vulnerable by consulting the vendor’s patch notes.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of the flaw. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting no known public exploitation. The likely attack vector is remote through an HTTP/2 client that can send specially crafted trailers; however, the exact conditions for exploitation are not defined in the supplied information, so the risk is inferred from the nature of the flaw and its severity rating.
OpenCVE Enrichment