Session Expiration Flaw in Envoy Proxy by Envoy
CVE-2025-55162
What is CVE-2025-55162?
Envoy Proxy has a vulnerability in its OAuth2 filter that fails to adequately handle session expiration, particularly during logout procedures. When certain cookie names are employed, the necessary Secure attribute is absent in the deletion headers sent by the filter. As a result, modern browsers disregard these invalid requests, leading to persistent session cookies even after a logout has been attempted. This flaw increases the risk of session hijacking, especially for users accessing shared computers, as subsequent users can inadvertently gain access to previous users' accounts and data. The issue has been rectified in specific new versions of Envoy Proxy.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
envoy >= 1.35.0, < 1.35.1 < 1.35.0, 1.35.1
envoy >= 1.34.0, < 1.34.5 < 1.34.0, 1.34.5
envoy >= 1.33.0, < 1.33.7 < 1.33.0, 1.33.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
