High severity7.5NVD Advisory· Published May 20, 2021· Updated Jun 17, 2026
CVE-2021-29258
CVE-2021-29258
Description
An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7=1.14.0+ 4 more
- (no CPE)range: =1.14.0
- cpe:2.3:a:envoyproxy:envoy:1.14.6:*:*:*:*:*:*:*
- cpe:2.3:a:envoyproxy:envoy:1.15.3:*:*:*:*:*:*:*
- cpe:2.3:a:envoyproxy:envoy:1.16.2:*:*:*:*:*:*:*
- cpe:2.3:a:envoyproxy:envoy:1.17.1:*:*:*:*:*:*:*
- Envoy/Envoydescription
Patches
Vulnerability mechanics
References
5- blog.envoyproxy.ionvdVendor Advisory
- github.com/envoyproxy/envoy/releases/tag/v1.14.0nvdThird Party Advisory
- github.com/envoyproxy/envoy/security/advisories/GHSA-rqvq-hxw5-776jnvdThird Party Advisory
- github.com/envoyproxy/envoy/security/advisories/GHSA-xw4q-6pj2-5gfgnvdNot ApplicableThird Party Advisory
- github.com/envoyproxy/envoy-setec/pull/230nvdBroken Link
News mentions
0No linked articles in our index yet.