Improper Null Termination
CVE-2025-66220
Summary
Envoy is a high-performance edge/middle/service proxy. In versions through 1.33.12, 1.34.x through 1.34.10, 1.35.x through 1.35.6, and 1.36.x through 1.36.2, Envoys mTLS certificate matcher for "match_typed_subject_alt_names" may incorrectly treat certificates containing an embedded null byte "\0" inside an OTHERNAME SAN value as valid matches.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-170 - Improper Null Termination
The software does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
References
Advisory Timeline
- Published