CVE-2025-66220: Envoyproxy Envoy
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte (\0) inside an OTHERNAME SAN value as valid matches.
Affected products
- Envoyproxy Envoy: before 1.33.13 (fixed in 1.33.13); from 1.34.0, before 1.34.11 (fixed in 1.34.11); from 1.35.0, before 1.35.7 (fixed in 1.35.7); from 1.36.0, before 1.36.3 (fixed in 1.36.3)
Published 2025-12-03. Last modified 2026-09-25.