An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.
https://github.com/envoyproxy/envoy/security/advisories/GHSA-xw4q-6pj2-5gfg
https://github.com/envoyproxy/envoy/security/advisories/GHSA-rqvq-hxw5-776j
https://github.com/envoyproxy/envoy/releases/tag/v1.14.0