CVE-2021-43825
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-43825 is a use-after-free vulnerability discovered in Envoy proxy that occurs when response filters increase response data and the increased data exceeds downstream buffer limits. The vulnerability was disclosed and patched in February 2022, affecting Envoy versions v1.21.0 and earlier. The issue has been assigned a CVSS score of 6.1 (Moderate severity) (GitHub Advisory).

Technical details

The vulnerability occurs when Envoy tracks the amount of buffered request and response data. While Envoy is designed to abort requests if buffered data exceeds limits by sending 413 or 500 responses, the operation may not abort correctly when the buffer overflows during response processing by the filter chain. This incorrect handling can result in accessing freed memory blocks. The vulnerability has been assigned a CVSS base score of 6.1 with the following metrics: Network attack vector, Low attack complexity, No privileges required, User interaction Required, Changed scope, and Low impact on both integrity and availability (GitHub Advisory).

Impact

The primary impact of this vulnerability is potential Denial of Service (DoS) attacks. When exploited, the vulnerability can lead to the application accessing freed memory blocks, which can cause service disruption (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Envoy versions 1.18.6, 1.19.3, 1.20.2, and 1.21.1. As a workaround, if upgrading is not immediately possible, users can disable filters that may modify a response body and increase its size (GitHub Advisory, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management