CVE-2022-21655: high-severity vulnerability in envoyproxy envoy
Incorrect handling of internal redirects results in crash in Envoy
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.1%
exploitation probability
1.1%top 34% of all CVEs
observed exploitation
nono source reports it
In short
Envoy proxy crashes when it tries to redirect traffic internally to a route that has direct response or redirect settings. This causes the service to stop working, disrupting traffic for users.
Technical detail
Internal redirect handling in Envoy's common router triggers a segmentation fault when the selected route is configured with direct response or redirect actions, resulting in process crash and denial of service. Exploitation requires the attacker to craft a request that triggers an internal redirect to a misconfigured route on the same listener.
Summary generated and translated by AI from the official description.
Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround turn off internal redirects if direct response entries are configured on the same listener.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
envoyproxy · envoyRelated CVEs — envoyproxy envoy
In the same product, most dangerous first.
CVE-2024-30255MEDIUMHTTP/2: CPU exhaustion due to CONTINUATION frame floodEPSS 87.8%CVE-2024-27919HIGHHTTP/2: memory exhaustion due to CONTINUATION frame floodEPSS 86.7%CVE-2021-29492HIGHBypass of path matching rules using escaped slash charactersEPSS 66.2%CVE-2021-32777HIGHIncorrect concatenation of multiple value request headers in ext-authz extensionEPSS 3.3%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2022-29225HIGHZip bomb vulnerability in EnvoyEPSS 1.6%