A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a chunk, and is no longer exploitable. No action is required as Classic Application Load Balancer service after 2025-04-26 is not vulnerable.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cloud.google.com/support/bulletins#gcp-2025-027 |
|
History
Mon, 08 Sep 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Mon, 08 Sep 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-444 |
Tue, 29 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google application Load Balancer |
|
| CPEs | cpe:2.3:a:google:application_load_balancer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google application Load Balancer |
|
| Metrics |
cvssV3_1
|
Fri, 16 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a chunk, and is no longer exploitable. No action is required as Classic Application Load Balancer service after 2025-04-26 is not vulnerable. | |
| Title | HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published: 2025-05-16T13:47:45.266Z
Updated: 2025-09-08T09:48:16.572Z
Reserved: 2025-05-12T17:25:11.459Z
Link: CVE-2025-4600
Updated: 2025-05-16T14:54:18.102Z
Status : Analyzed
Published: 2025-05-16T14:15:32.580
Modified: 2025-09-26T17:18:42.847
Link: CVE-2025-4600
No data.