GPU VulnDB

Database/Container, Kubernetes & orchestration

Envoy: crash when remote JWKS fetch fails with multiple JWT tokens and allow_missing_or_failed

CVSS 6.5CVE-2025-64527Container, Kubernetes & orchestrationcurated

Impact

A re-entry bug in JwksFetcherImpl crashes Envoy when the JWT filter is configured with remote JWKS fetching and allow_missing_or_failed, a request carries multiple JWT tokens, and the JWKS fetch fails. The crash takes down the proxy process, so every route behind that Envoy - inference endpoints, internal APIs, mesh sidecar traffic - drops with it. It is reachable by sending an ordinary request at a moment when the JWKS endpoint is unreachable, which an attacker can often arrange or simply wait for. Availability only; no disclosure or code execution. Deployments that do not use remote JWKS fetching with allow_missing_or_failed are not affected.

Who can reach it

Anyone who can send a request through an affected Envoy listener, with two or more JWT tokens in the headers, while the remote JWKS fetch fails. The CVSS vector assumes low privileges; no valid token is required since the failure path is the one that crashes.

What to do

Upgrade to a release above 1.33.12, 1.34.10, 1.35.6, or 1.36.2 on your branch, then restart or roll the Envoy fleet - a rolling restart of gateway pods and sidecars, no node action needed. If you cannot upgrade immediately, either disable allow_missing_or_failed on the JWT filter or switch to a local JWKS instead of remote fetching to remove the affected path.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.