CVE-2025-30157

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the failure of a websocket handshake will trigger a local reply leading to the crash of Envoy. This vulnerability is fixed in 1.33.1, 1.32.4, 1.31.6, and 1.30.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:1.33.0:*:*:*:*:*:*:*

History

01 Apr 2025, 20:22

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Envoyproxy
Envoyproxy envoy
Summary
  • (es) Envoy es un proxy de alto rendimiento para servicios perimetrales, intermedios y de borde, nativo de la nube. En versiones anteriores a las 1.33.1, 1.32.4, 1.31.6 y 1.30.10, el filtro HTTP ext_proc de Envoy corría el riesgo de bloquearse si se enviaba una respuesta local al servidor externo debido a un problema de duración del filtro. Un fallo en el protocolo de enlace websocket desencadenaba una respuesta local que provocaba el bloqueo de Envoy. Esta vulnerabilidad se corrigió en las versiones 1.33.1, 1.32.4, 1.31.6 y 1.30.10.
References () https://github.com/envoyproxy/envoy/commit/8eda1b8ef5ba8663d16a737ab99458c039a9b53c - () https://github.com/envoyproxy/envoy/commit/8eda1b8ef5ba8663d16a737ab99458c039a9b53c - Patch
References () https://github.com/envoyproxy/envoy/security/advisories/GHSA-cf3q-gqg7-3fm9 - () https://github.com/envoyproxy/envoy/security/advisories/GHSA-cf3q-gqg7-3fm9 - Vendor Advisory
CPE cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*
cpe:2.3:a:envoyproxy:envoy:1.33.0:*:*:*:*:*:*:*

21 Mar 2025, 16:15

Type Values Removed Values Added
References () https://github.com/envoyproxy/envoy/security/advisories/GHSA-cf3q-gqg7-3fm9 - () https://github.com/envoyproxy/envoy/security/advisories/GHSA-cf3q-gqg7-3fm9 -

21 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 15:15

Updated : 2025-04-01 20:22


NVD link : CVE-2025-30157

Mitre link : CVE-2025-30157

CVE.ORG link : CVE-2025-30157


JSON object : View

Products Affected

envoyproxy

  • envoy
CWE
CWE-460

Improper Cleanup on Thrown Exception

NVD-CWE-noinfo