CVE-2025-66220Medium· 5.0▾ SunlitEnvoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null by…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte (\0) inside an OTHERNAME SAN value as valid matches.
envoy < 1.33.13envoy >= 1.34.0, < 1.34.11envoy >= 1.35.0, < 1.35.7envoy >= 1.36.0, < 1.36.3Upgrade past the affected range:
envoy 1.36.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64527Medium· 6.5Envoy is a high-performance edge/middle/service proxy
CVE-2026-73551Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-73553High· 7.5Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-73511Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-73546High· 7.4Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-73512High· 7.5Envoy is an open source edge and service proxy designed for cloud-native applications