Skip to content

x/vulndb: potential Go vuln in github.com/envoyproxy/envoy: GHSA-rj35-4m94-77jh #4195

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-rj35-4m94-77jh references a vulnerability in the following Go modules:

Module
github.com/envoyproxy/envoy

Description:

Summary

Forwarding of early CONNECT data in TCP proxy mode.

Details

Per RFC 7231-4.3.6 the sender of CONNECT (and all inbound proxies) switch to tunnel mode only after receiving 2xx response. However in TCP proxy mode, Envoy accepts client data before it has issued a 2xx response and eagerly proxies it to an established TCP connection. This creates possibility of a de-synchronized tunnel state if a proxy upstream from Envoy responds with a status other an 2xx.

The RFC does not specify the behavior in case an early CONNECT data ...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/envoyproxy/envoy
      non_go_versions:
        - introduced: TODO (earliest fixed "1.33.13", vuln range "<= 1.33.12")
        - introduced: TODO (earliest fixed "1.34.11", vuln range ">= 1.34.0, <= 1.34.10")
        - introduced: TODO (earliest fixed "1.35.7", vuln range ">= 1.35.0, <= 1.35.6")
        - introduced: TODO (earliest fixed "1.36.3", vuln range ">= 1.36.0, <= 1.36.2")
      vulnerable_at: 1.36.3
summary: Envoy forwards early CONNECT data in TCP proxy mode in github.com/envoyproxy/envoy
cves:
    - CVE-2025-64763
ghsas:
    - GHSA-rj35-4m94-77jh
references:
    - advisory: https://github.com/advisories/GHSA-rj35-4m94-77jh
    - advisory: https://github.com/envoyproxy/envoy/security/advisories/GHSA-rj35-4m94-77jh
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-64763
notes:
    - fix: 'module merge error: could not merge versions of module github.com/envoyproxy/envoy: invalid or non-canonical semver version (found TODO (earliest fixed "1.33.13", vuln range "<= 1.33.12"))'
source:
    id: GHSA-rj35-4m94-77jh
    created: 2025-12-05T19:01:22.49237108Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions