CVE-2021-28682: Envoyproxy Envoy

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

Affected products

  • Envoyproxy Envoy: version 1.14.6 only; version 1.15.3 only; version 1.16.2 only; version 1.17.1 only

Published 2021-05-20. Last modified 2026-06-17.