{"id":"CVE-2021-32778","details":"Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedure for resetting a HTTP/2 stream has O(N^2) complexity, leading to high CPU utilization when a large number of streams are reset. Deployments are susceptible to Denial of Service when Envoy is configured with high limit on H/2 concurrent streams. An attacker wishing to exploit this vulnerability would require a client opening and closing a large number of H/2 streams. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to reduce time complexity of resetting HTTP/2 streams. As a workaround users may limit the number of simultaneous HTTP/2 dreams for upstream and downstream peers to a low number, i.e. 100.","aliases":["BIT-envoy-2021-32778","GHSA-3xh3-33v5-chcc"],"modified":"2026-08-07T19:48:35.418156Z","published":"2021-08-24T21:15:09.553Z","references":[{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-3xh3-33v5-chcc"},{"type":"ADVISORY","url":"https://www.envoyproxy.io/docs/envoy/v1.19.0/version_history/version_history"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"8fb3cb86082b17144a80402f5367ae65f06083bd"},{"fixed":"72ec3eed50b4154cb6d2251667b4c1c1ddfaa266"},{"introduced":"5c801b25cae04f06bf48248c90e87d623d7a6283"},{"fixed":"0de60452be1fa329c16076916b6bfe1f672aeed4"},{"introduced":"345ffe37148b7a35b6e8e04db0300463689e3ff1"},{"fixed":"bef18019d8fc33a4ed6aca3679aff2100241ac5e"},{"introduced":"68fe53a889416fd8570506232052b06f5a531541"},{"last_affected":"68fe53a889416fd8570506232052b06f5a531541"}],"database_specific":{"extracted_events":[{"introduced":"1.16.0"},{"fixed":"1.16.5"},{"introduced":"1.17.0"},{"fixed":"1.17.4"},{"introduced":"1.18.0"},{"fixed":"1.18.4"},{"introduced":"1.19.0"},{"last_affected":"1.19.0"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*","cpe:2.3:a:envoyproxy:envoy:1.19.0:*:*:*:*:*:*:*"]}}],"versions":["1.19.0","v1.19.0","v1.16.4","v1.17.3","v1.18.3","v1.17.2","v1.18.2","v1.16.3","v1.18.1","v1.18.0","v1.17.1","v1.17.0","v1.16.2","v1.16.1","v1.16.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32778.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}