A vulnerability has been found in Envoy up to 1.33.11/1.34.9/1.35.5/1.36.1 and classified as critical. Impacted is the function
per_connection_buffer_limit_bytes
. Performing manipulation results in use after free.
This vulnerability is known as CVE-2025-62504. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.