{"id":"GHSA-gjcg-vrxg-xmgv","summary":"Incorrect handling of H2 GOAWAY + SETTINGS frames","details":"Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event.  \n\n### Impact\nThis can lead to a DoS in the presence of untrusted *upstream* servers.\n\n### Patches\n0.15.1 contains an upgraded envoy binary with this vulnerability patched.\n\n### Workarounds\nIf only trusted upstreams are configured, there is not substantial risk of this condition being triggered.\n\n### References\n[envoy GSA](https://github.com/envoyproxy/envoy/security/advisories/GHSA-j374-mjrw-vvp8)\n[envoy CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32780)\n[envoy announcement](https://groups.google.com/g/envoy-announce/c/5xBpsEZZDfE/m/wD05NZBbAgAJ)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [pomerium/pomerium](https://github.com/pomerium/pomerium/issues)\n* Email us at [security@pomerium.com](mailto:security@pomerium.com)\n\n","aliases":["BIT-envoy-2021-39162","CVE-2021-39162","GO-2022-0933"],"modified":"2026-02-04T02:55:29.909324Z","published":"2021-09-10T17:54:01Z","related":["CVE-2021-39162"],"database_specific":{"nvd_published_at":"2021-09-09T22:15:00Z","severity":"HIGH","cwe_ids":["CWE-754"],"github_reviewed_at":"2021-09-10T16:32:16Z","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-j374-mjrw-vvp8"},{"type":"WEB","url":"https://github.com/pomerium/pomerium/security/advisories/GHSA-gjcg-vrxg-xmgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39162"},{"type":"PACKAGE","url":"https://github.com/pomerium/pomerium"},{"type":"WEB","url":"https://groups.google.com/g/envoy-announce/c/5xBpsEZZDfE/m/wD05NZBbAgAJ"}],"affected":[{"package":{"name":"github.com/pomerium/pomerium","ecosystem":"Go","purl":"pkg:golang/github.com/pomerium/pomerium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-gjcg-vrxg-xmgv/GHSA-gjcg-vrxg-xmgv.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"}]}