<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T12:57:36.387402+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-envoy-2025-64763</id>
    <title>BIT-envoy-2025-64763 — Envoy forwards early CONNECT data in TCP proxy mode</title>
    <updated>2026-10-08T12:57:36.439441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: envoy</p>
<p>Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwards that data to the upstream TCP connection. If a forwarding proxy upstream from Envoy then responds with a non-2xx status, this can cause a de-synchronized CONNECT tunnel state. By default Envoy continues to allow early CONNECT data to avoid disrupting existing deployments. The envoy.reloadable_features.reject_early_connect_data runtime flag can be set to reject CONNECT requests that send data before a 2xx response when intermediaries upstream from Envoy may reject establishment of a CONNECT tunnel.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-envoy-2025-64763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262469</id>
    <title>EUVD-2026-262469</title>
    <updated>2026-10-08T12:57:36.439553+00:00</updated>
    <content>EUVD-2026-262469</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64763</id>
    <title>fkie_cve-2025-64763</title>
    <updated>2026-10-08T12:57:36.439570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwards that data to the upstream TCP connection. If a forwarding proxy upstream from Envoy then responds with a non-2xx status, this can cause a de-synchronized CONNECT tunnel state. By default Envoy continues to allow early CONNECT data to avoid disrupting existing deployments. The envoy.reloadable_features.reject_early_connect_data runtime flag can be set to reject CONNECT requests that send data before a 2xx response when intermediaries upstream from Envoy may reject establishment of a CONNECT tunnel.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rj35-4m94-77jh</id>
    <title>GHSA-rj35-4m94-77jh — Envoy forwards early CONNECT data in TCP proxy mode</title>
    <updated>2026-10-08T12:57:36.439599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/envoyproxy/envoy</p>
<p>## Summary</p>
<p>Forwarding of early CONNECT data in TCP proxy mode.</p>
<p>## Details</p>
<p>Per [RFC 7231-4.3.6](https://www.rfc-editor.org/rfc/rfc7231#section-4.3.6) the sender of CONNECT (and all inbound proxies)  switch to tunnel mode only after receiving 2xx response. However in TCP proxy mode, Envoy accepts client data before it has issued a 2xx response and eagerly proxies it to an established TCP connection. This creates possibility of a de-synchronized tunnel state if a proxy upstream from Envoy responds with a status other an 2xx.</p>
<p>The RFC does not specify the behavior in case an early CONNECT data is received and early CONNECT data is common as a latency reduction mechanism. To prevent disruption to existing deployments Envoy will by default allow early CONNECT data. Setting the `envoy.reloadable_features.reject_early_connect_data` runtime flag to `true` will cause CONNECT requests that send data before 2xx response to be rejected. This options should be enabled if there are intermediaries upstream from Envoy that may reject establishment of a CONNECT tunnel.</p>
<p>## Impact</p>
<p>De-synchronization of CONNECT tunnel state if a forwarding proxy upstream from Envoy responds with a non 2xx status.</p>
<p>## Attack vector(s)
Sending data for a CONNECT request before receiving 2xx response.</p>
<p>## Patches
Users should upgrade to v1.36.3, v1.35.7, v1.34.11 or v1.33.13</p>
<p>## Credits</p>
<p>[chasingimpact](https://github.com/chasingimpact) (Patrick)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rj35-4m94-77jh"/>
  </entry>
</feed>
