---
id: CVE-2025-62409
title: 'Envoy is a cloud-native, open source edge and service proxy'
summary: >-
  Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1,
  1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially
  trigger TCP connection pool crashes due to flow control management in Envoy.
  It will …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: envoyproxy
product: envoy
affected:
  - envoy < 1.33.11
  - 'envoy >= 1.34.0, < 1.34.9'
  - 'envoy >= 1.35.0, < 1.35.5'
  - envoy = 1.36.0
patched:
  - envoy 1.35.5
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62409'
references:
  - url: >-
      https://github.com/envoyproxy/envoy/security/advisories/GHSA-pq33-4jxh-hgm3
    label: security-advisories@github.com
  - url: >-
      https://github.com/envoyproxy/envoy/security/advisories/GHSA-pq33-4jxh-hgm3
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00456
epssPercentile: 0.37562
ingestedAt: '2026-10-09T12:53:29.051Z'
---

## Overview

Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP connection pool crashes due to flow control management in Envoy. It will happen when the connection is closing but upstream data is still coming, resulting in a buffer watermark callback nullptr reference. The vulnerability impacts TCP proxy and HTTP 1 & 2 mixed use cases based on ALPN. This vulnerability is fixed in 1.36.1, 1.35.5, 1.34.9, and 1.33.10.

## Affected

- `envoy < 1.33.11`
- `envoy >= 1.34.0, < 1.34.9`
- `envoy >= 1.35.0, < 1.35.5`
- `envoy = 1.36.0`

## Remediation

Upgrade past the affected range:

- `envoy 1.35.5`
