Envoyproxy: openshift service mesh envoy http header sanitization bypass leading to dos and unauthorized access
Published Jan 28, 2025
7.1
HIGHCVSS 3.1
EPSS 0.41%
Description
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | OpenShift Service Mesh 2 | affected |
|
- 2.5.6
- 2.6.3
No data.
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel8
Affected
OpenShift Service Mesh 2
openshift-service-mesh/proxyv2-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/proxyv2-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Red Hat statement
This IMPORTANT flaw in OpenShift Service Mesh 2.6.3 and 2.5.6 allows an attacker to bypass HTTP header sanitization in Envoy. This can lead to rate-limiter avoidance, access-control bypass, and resource exhaustion, potentially resulting in denial-of-service or unauthorized access within the service mesh environment. The vulnerability impacts deployments utilizing these specific versions of OpenShift Service Mesh.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (4)
- https://access.redhat.com/security/cve/CVE-2025-0752 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2339115 issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-0752
- https://www.cve.org/CVERecord?id=CVE-2025-0752
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-0752 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2339115 | issue-trackingx_refsource_REDHATVendor AdvisoryIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-0752 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-0752 |
Change history (0)
No recorded changes yet.