Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30157


Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.


Published

2025-03-21T15:15:43.290

Last Modified

2025-04-01T20:22:34.500

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-460
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application envoyproxy envoy < 1.30.10 Yes
Application envoyproxy envoy < 1.31.6 Yes
Application envoyproxy envoy < 1.32.4 Yes
Application envoyproxy envoy 1.33.0 Yes

References