Impact
The vulnerability triggers a crash in Envoy when handling IPv6 addresses from HTTP/3 client requests in original destination‑socket (DST) clusters. The crash results from a memory corruption flaw identified as CWE‑119, leading to a denial of service by terminating the Envoy process and disrupting traffic forwarding.
Affected Systems
The affected product is the Envoy proxy, which is commonly deployed as an edge or service mesh component. No specific vendor versions are listed by the CNA, so any deployment that uses an unpatched Envoy release and supports HTTP/3 over IPv6 is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score is not available so the probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the crash occurs upon receipt of an HTTP/3 request containing certain IPv6 destinations, the likely attacker can trigger the failure remotely by sending crafted traffic. Operational impact is service interruption rather than privilege escalation or data exfiltration.
OpenCVE Enrichment