Flow Control Management Vulnerability in Envoy Proxy by Envoy
CVE-2025-62409
What is CVE-2025-62409?
The Envoy Proxy, a cloud-native edge and service proxy, has a vulnerability related to flow control management that can lead to TCP connection pool crashes. This issue arises when a connection is closing while upstream data continues to flow, causing a null reference in the buffer watermark callback. Affected scenarios include TCP proxy and HTTP/1 & 2 mixed usage with ALPN. The issue is addressed in versions 1.36.1, 1.35.5, 1.34.9, and 1.33.10.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
envoy >= 1.36.0, < 1.36.1 < 1.36.0, 1.36.1
envoy >= 1.35.0, < 1.35.5 < 1.35.0, 1.35.5
envoy >= 1.34.0, < 1.34.9 < 1.34.0, 1.34.9
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
