A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
CVE ID: CVE-2025-0752
Vendor: Red Hat
Product: OpenShift Service Mesh 2
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 16.0% (scored less or equal to compared to others)
EPSS Date: 2025-02-27 (when was this score calculated)