{"id":"GHSA-rj35-4m94-77jh","summary":"Envoy forwards early CONNECT data in TCP proxy mode","details":"## Summary\n\nForwarding of early CONNECT data in TCP proxy mode.\n\n## Details\n\nPer [RFC 7231-4.3.6](https://www.rfc-editor.org/rfc/rfc7231#section-4.3.6) the sender of CONNECT (and all inbound proxies)  switch to tunnel mode only after receiving 2xx response. However in TCP proxy mode, Envoy accepts client data before it has issued a 2xx response and eagerly proxies it to an established TCP connection. This creates possibility of a de-synchronized tunnel state if a proxy upstream from Envoy responds with a status other an 2xx.\n\nThe RFC does not specify the behavior in case an early CONNECT data is received and early CONNECT data is common as a latency reduction mechanism. To prevent disruption to existing deployments Envoy will by default allow early CONNECT data. Setting the `envoy.reloadable_features.reject_early_connect_data` runtime flag to `true` will cause CONNECT requests that send data before 2xx response to be rejected. This options should be enabled if there are intermediaries upstream from Envoy that may reject establishment of a CONNECT tunnel. \n\n## Impact\n\nDe-synchronization of CONNECT tunnel state if a forwarding proxy upstream from Envoy responds with a non 2xx status.\n\n## Attack vector(s)\nSending data for a CONNECT request before receiving 2xx response.\n\n## Patches\nUsers should upgrade to v1.36.3, v1.35.7, v1.34.11 or v1.33.13\n\n## Credits\n\n[chasingimpact](https://github.com/chasingimpact) (Patrick)","aliases":["BIT-envoy-2025-64763","CVE-2025-64763"],"modified":"2025-12-10T20:19:27.162055Z","published":"2025-12-05T18:12:51Z","database_specific":{"github_reviewed_at":"2025-12-05T18:12:51Z","nvd_published_at":"2025-12-03T18:15:47Z","cwe_ids":["CWE-693"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-rj35-4m94-77jh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64763"},{"type":"PACKAGE","url":"https://github.com/envoyproxy/envoy"}],"affected":[{"package":{"name":"github.com/envoyproxy/envoy","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/envoy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.36.0"},{"fixed":"1.36.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.36.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-rj35-4m94-77jh/GHSA-rj35-4m94-77jh.json"}},{"package":{"name":"github.com/envoyproxy/envoy","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/envoy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.35.0"},{"fixed":"1.35.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-rj35-4m94-77jh/GHSA-rj35-4m94-77jh.json","last_known_affected_version_range":"\u003c= 1.35.6"}},{"package":{"name":"github.com/envoyproxy/envoy","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/envoy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.34.0"},{"fixed":"1.34.11"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.34.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-rj35-4m94-77jh/GHSA-rj35-4m94-77jh.json"}},{"package":{"name":"github.com/envoyproxy/envoy","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/envoy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.33.13"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.33.12","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-rj35-4m94-77jh/GHSA-rj35-4m94-77jh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}