# CVE-2025-30157

## Summary

- **CVE ID:** CVE-2025-30157
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
- **CWE:** CWE-460
- **Published:** Mar 21, 2025
- **Last Modified:** Mar 12, 2026

## Description

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.

## Affected Products

- envoyproxy — envoy (>= 1.33.0, < 1.33.1)
- envoyproxy — envoy (>= 1.32.0, < 1.32.4)
- envoyproxy — envoy (>= 1.31.0, < 1.31.6)
- envoyproxy — envoy (< 1.30.10)

## References

- [CNA](https://github.com/envoyproxy/envoy/security/advisories/GHSA-cf3q-gqg7-3fm9)
- [CNA](https://github.com/envoyproxy/envoy/commit/8eda1b8ef5ba8663d16a737ab99458c039a9b53c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 35.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._