Stay organized with collections
Save and categorize content based on your preferences.
All security bulletins for Cloud Load Balancing are described here. For all
security bulletins related to Google Cloud products, see Security
Bulletins.
A security vulnerability was detected in the
classic Application Load Balancer service prior to April 26, 2025.
What should I do?
No customer action is required. The issue was resolved in the
Classic Application Load Balancer service on April 26, 2025.
What vulnerabilities are being addressed?
CVE-2025-4600
allowed attackers to smuggle requests to classic Application Load Balancers due to
incorrect parsing of oversized chunk bodies. When parsing the request
body of an HTTP request using chunked transfer-encoding, the
classic Application Load Balancer allows oversized chunk bodies. Consequently, it was
feasible to hide bytes within this ignored trailing data that an upstream
HTTP server might incorrectly interpret as a line terminator. This
vulnerability was addressed within the classic Application Load Balancer service on
April 26, 2025 through improved input validation and parsing logic.
We're here to help
If you have any questions or require assistance, contact
Cloud Customer Care.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[],[],null,["# Security bulletins for Cloud Load Balancing\n\nAll security bulletins for Cloud Load Balancing are described here. For all\nsecurity bulletins related to Google Cloud products, see [Security\nBulletins](/support/bulletins).\n\n\n[Use this XML feed to subscribe to security bulletins for this page.](https://cloud.google.com/feeds/cloud-load-balancing-security-bulletins.xml)\n\nGCP-2025-027\n------------\n\n**Published:**2025-05-16\n\n### Description"]]