CVE-2025-30157: Envoy crashes when HTTP ext_proc processes local replies
Envoy’s ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter’s life time issue. A known situation is the fail of a websocket handshake will trigger a local reply leading to the crash of Envoy.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-30157 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →