#VU114762 Use-after-free in envoy - CVE-2025-54588
Published: September 3, 2025
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the Dynamic Forward Proxy implementation when a completion callback for a DNS resolution triggers new DNS resolutions or removes existing pending resolutions. A remote attacker can perform a denial of service attack.