Skip to main content

Improper Null Termination

CVE-2025-66220

Severity High
Score 7.1/10

Summary

Envoy is a high-performance edge/middle/service proxy. In versions through 1.33.12, 1.34.x through 1.34.10, 1.35.x through 1.35.6, and 1.36.x through 1.36.2, Envoys mTLS certificate matcher for "match_typed_subject_alt_names" may incorrectly treat certificates containing an embedded null byte "\0" inside an OTHERNAME SAN value as valid matches.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-170 - Improper Null Termination

The software does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

Advisory Timeline

  • Published