Impact
A NULL pointer dereference in the Envoy ext_authz module can cause the component to crash when it receives an HTTP CONNECT request that omits the required :path pseudo‑header, leading to a denial of service for clients using that connection.
Affected Systems
Any installation of Envoy that includes the ext_authz filter is potentially vulnerable; the specific patched or affected versions are not listed in the available data.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high severity. No EPSS score is available, and the vulnerability is not catalogued in CISA’s KEV database, suggesting it may not yet be widely exploited. The likely attack vector is a network‑based request that can be sent to the Envoy proxy, requiring access to send an HTTP CONNECT request without a :path header. Exploiting this weakness would result in a crash of ext_authz and a temporary loss of service for the affected proxy.
OpenCVE Enrichment