TCP Proxy Mode Vulnerability in Envoy Proxy by Envoy Proxy Maintainers
CVE-2025-64763
What is CVE-2025-64763?
The Envoy Proxy, when configured in TCP proxy mode to manage CONNECT requests, improperly accepts client data prior to issuing a 2xx response. This behavior can lead to severe desynchronization in the CONNECT tunnel state when an upstream forwarding proxy responds with a non-2xx status. While Envoy is designed to allow early CONNECT data to maintain compatibility with existing deployments, users can mitigate risks by enabling the envoy.reloadable_features.reject_early_connect_data runtime flag, which rejects such requests and improves state consistency.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
envoy >= 1.36.0, <= 1.36.2 <= 1.36.0, 1.36.2
envoy >= 1.35.0, <= 1.35.6 <= 1.35.0, 1.35.6
envoy >= 1.34.0, <= 1.34.10 <= 1.34.0, 1.34.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
