Metrics
Affected Vendors & Products
Wed, 29 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* cpe:2.3:a:envoyproxy:envoy:1.36.0:*:*:*:*:*:*:* | |
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
Tue, 21 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Envoyproxy Envoyproxy envoy | |
| Vendors & Products | Envoyproxy Envoyproxy envoy | 
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 16 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP connection pool crashes due to flow control management in Envoy. It will happen when the connection is closing but upstream data is still coming, resulting in a buffer watermark callback nullptr reference. The vulnerability impacts TCP proxy and HTTP 1 & 2 mixed use cases based on ALPN. This vulnerability is fixed in 1.36.1, 1.35.5, 1.34.9, and 1.33.10. | |
| Title | Envoy allows large requests and responses to cause TCP connection pool crash | |
| Weaknesses | CWE-476 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-16T17:47:25.585Z
Updated: 2025-10-16T19:22:45.332Z
Reserved: 2025-10-13T16:26:12.178Z
Link: CVE-2025-62409
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-16T18:27:19.068Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-10-16T18:15:39.583
Modified: 2025-10-29T19:55:48.173
Link: CVE-2025-62409
 Redhat
                        Redhat