Skip to content

Large requests and responses can cause TCP connection pool crash

High
phlax published GHSA-pq33-4jxh-hgm3 Oct 15, 2025

Package

Envoy (Envoy Proxy)

Affected versions

<= 1.36.0

Patched versions

1.36.1 1.35.5 1.34.9 1.33.11

Description

Summary

Large requests and responses can potentially trigger TCP connection pool crashes due to flow control management in Envoy, and it will impact TCP proxy and HTTP 1 & 2 mixed use cases based on ALPN

Details

It will happen when the connection is closing but upstream data is still coming, resulting in a buffer watermark callback nullptr reference.

PoC

e.g., slow clients send large enough requests and then close the connection to Envoy TCP proxy.

Impact

DoS and crash.

Severity

High

CVE ID

CVE-2025-62409

Weaknesses

No CWEs

Credits