Miggo Logo

CVE-2025-25294: Envoy Gateway Log Injection Vulnerability

5.3

CVSS Score
3.1

Basic Information

EPSS Score
0.37808%
Published
3/6/2025
Updated
3/11/2025
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/envoyproxy/gatewaygo< 1.2.71.2.7
github.com/envoyproxy/gatewaygo>= 1.3.0-rc.1, < 1.3.11.3.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t In *ll *nvoy **t*w*y v*rsions prior to *.*.* *n* *.*.* * ****ult *nvoy Proxy ****ss lo* *on*i*ur*tion is us**. T*is *orm*t is vuln*r**l* to lo* inj**tion *tt**ks. I* t** *tt**k*r us*s * sp**i*lly *r**t** us*r-***nt w*i** p*r*orms json in

Reasoning

No *n*lysis *v*il**l*