CVE-2025-30157
Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-460
- Published
- 2025-03-21
- Last modified
- 2026-03-12
Affected products
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
- envoyproxy envoy
Weakness type
Related vulnerabilities
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not...
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is...
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes