CVE-2021-39162: Incorrect handling of H2 GOAWAY + SETTINGS frames

Published Sep 9, 2021
·
Updated

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted upstream servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial risk of this condition being triggered.

Affected Software

3 affected components
Envoyproxy Envoy<1.18.4
Envoyproxy Envoy=1.19.0
Pomerium pomerium=0.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pomerium to a version that resolves this vulnerability.

    Fixed in 0.15.1
  2. Compensating control

    Ensure only trusted upstreams are configured to reduce the risk of the DoS condition being triggered (untrusted upstream servers can trigger the H2 GOAWAY + SETTINGS handling issue).

Event History

Sep 9, 2021
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2021-39162?

CVE-2021-39162 is a vulnerability in the Pomerium open source identity-aware access proxy, based on the Envoy proxy, that can lead to a denial-of-service (DoS) attack.

2

How does CVE-2021-39162 impact Envoy?

CVE-2021-39162 can cause an abnormal termination of Envoy if an H/2 GOAWAY and SETTINGS frame are received in the same IO event, leading to a DoS attack.

3

Is my version of Envoy affected by CVE-2021-39162?

Versions of Envoy up to and excluding 1.18.4 are affected by CVE-2021-39162.

4

Is my version of Pomerium affected by CVE-2021-39162?

Pomerium version 0.15.0 is affected by CVE-2021-39162.

5

How can I fix CVE-2021-39162?

To fix CVE-2021-39162, it is recommended to upgrade to a version of Envoy that is not affected or apply the necessary security patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203