Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-0752


A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.


Published

2025-01-28T10:15:09.493

Last Modified

2025-07-31T18:29:53.110

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-444

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat openshift_service_mesh 2.5.6 Yes
Application redhat openshift_service_mesh 2.6.3 Yes

References