Access Control Vulnerabilities in OpenShift Service Mesh by Red Hat
CVE-2025-0752
6.3MEDIUM
What is CVE-2025-0752?
A flaw in OpenShift Service Mesh versions 2.6.3 and 2.5.6 has been identified, which may allow for rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and potential replay attacks. This vulnerability stems from inadequate sanitization of HTTP headers within Envoy, necessitating urgent attention to patch affected systems to prevent exploitation.