High severity7.1NVD Advisory· Published Jan 28, 2025· Updated Jun 17, 2026
CVE-2025-0752
CVE-2025-0752
Description
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:redhat:openshift_service_mesh:2.5.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_service_mesh:2.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_service_mesh:2.6.3:*:*:*:*:*:*:*
- Range: 2.6.3, 2.5.6
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2025-0752nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdVendor Advisory
News mentions
0No linked articles in our index yet.