CVE-2025-4600

HIGH

Google Cloud Classic App LB - RCE

Title source: llm
STIX 2.1

Description

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue was fixed by disallowing stray data after a chunk, and is no longer exploitable. No action is required as Classic Application Load Balancer service after 2025-04-26 is not vulnerable.

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (1)
google/application_load_balancer < 2025-04-26
Published May 16, 2025
Tracked Since Feb 18, 2026