We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-30157

Envoy crashes when HTTP ext_proc processes local replies



Description

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.

Reserved 2025-03-17 | Published 2025-03-21 | Updated 2025-03-21 | Assigner GitHub_M


MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-460: Improper Cleanup on Thrown Exception

Product status

>= 1.33.0, < 1.33.1
affected

>= 1.32.0, < 1.32.4
affected

>= 1.31.0, < 1.31.6
affected

< 1.30.10
affected

References

github.com/.../envoy/security/advisories/GHSA-cf3q-gqg7-3fm9

github.com/...ommit/8eda1b8ef5ba8663d16a737ab99458c039a9b53c

cve.org (CVE-2025-30157)

nvd.nist.gov (CVE-2025-30157)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-30157

Support options

Helpdesk Chat, Email, Knowledgebase