Intel

AIKIDO-2025-10138

github.com/envoyproxy/gateway is vulnerable to Improper Output Neutralization for Logs (Log Injection)

Improper Output Neutralization for Logs (Log Injection)CVE-2025-25294 Published Mar 6, 2025

50

Medium Risk

This Affects:

GOgithub.com/envoyproxy/gateway
0.5.0 - 1.3.0
Fixed in 1.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of the github.com/envoyproxy/gateway library are vulnerable to log injection when using the default access log. An attacker can manipulate log entries by injecting malicious input, leading to corrupted log files. This vulnerability can be exploited to obscure malicious activity, disrupt log analysis, and forge log entries, potentially impacting security monitoring and forensic investigations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/envoyproxy/gateway is vulnerable to Improper Output Neutralization for Logs (Log Injection) in versions 0.5.0 - 1.3.0.

How to fix this

Upgrade the github.com/envoyproxy/gateway library to the patch version.