#VU119111 State Issues in envoy - CVE-2025-64763
Published: December 3, 2025
envoy
Cloud Native Computing Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a state issue related to forwarding of early CONNECT data in TCP proxy mode. A remote attacker can trigger de-synchronization of CONNECT tunnel state if a forwarding proxy upstream from Envoy responds with a non 2xx status and gain access to sensitive information.