CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Envoyproxy Remove filter Clear all
CVE-2026-73553 HIGH

Envoy: RBAC Authorization Bypass via Path Parameters

CVSS 7.5 EPSS 0.52% Sep 21, 2026
CVE-2026-73551 MEDIUM

Envoy: Path normalization does not handle dot and dotdot segments with parameters

CVSS 5.3 EPSS 0.55% Sep 21, 2026
CVE-2026-73511 MEDIUM

Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache…

CVSS 5.3 EPSS 0.55% Sep 21, 2026
CVE-2026-73552 HIGH

Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values

CVSS 7.5 EPSS 0.66% Sep 21, 2026
CVE-2026-73550 HIGH

Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy

CVSS 7.5 EPSS 0.58% Sep 21, 2026
CVE-2026-73549 MEDIUM

Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters

CVSS 5.3 EPSS 0.60% Sep 21, 2026
CVE-2026-73548 HIGH

Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool

CVSS 7.5 EPSS 0.48% Sep 21, 2026
CVE-2026-73546 HIGH

Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)

CVSS 7.4 EPSS 0.60% Sep 21, 2026
CVE-2026-73513 HIGH

Envoy: oghttp2 upstream trailers incorrect handling

CVSS 7.5 EPSS 0.47% Sep 21, 2026
CVE-2026-73512 HIGH

Envoy: use-after-free in QUIC on internal redirects

CVSS 7.5 EPSS 0.83% Sep 21, 2026
CVE-2026-50572 MEDIUM

Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault

CVSS 5.9 EPSS 0.68% Sep 21, 2026
CVE-2026-48521 MEDIUM

Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null

CVSS 5.9 EPSS 0.70% Sep 21, 2026
CVE-2026-73547 HIGH

Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check

CVSS 7.5 EPSS 0.83% Sep 21, 2026
CVE-2026-53714 HIGH

Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode

CVSS 7.4 EPSS 0.35% Sep 14, 2026
Go
CVE-2026-53716 MEDIUM

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

CVSS 6.5 EPSS 0.71% Sep 14, 2026
Go
CVE-2026-53715 MEDIUM

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

CVSS 5.3 EPSS 0.47% Sep 14, 2026
Go
CVE-2026-53719 MEDIUM

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

CVSS 6.5 EPSS 0.71% Sep 14, 2026
Go
CVE-2026-53718 MEDIUM

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

CVSS 6.4 EPSS 0.41% Sep 14, 2026
Go
CVE-2026-53713 CRITICAL

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

CVSS 9.1 EPSS 0.43% Sep 14, 2026
Go
CVE-2026-53717 MEDIUM

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

CVSS 6.5 EPSS 0.71% Sep 14, 2026
Go
CVE-2026-48090 MEDIUM

Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)

CVSS 5.9 EPSS 0.58% Jun 26, 2026
CVE-2026-47220 HIGH

Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format

CVSS 7.5 EPSS 0.66% Jun 26, 2026
CVE-2026-47205 MEDIUM

Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides

CVSS 5.9 EPSS 0.39% Jun 26, 2026
CVE-2026-47692 MEDIUM

Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream

CVSS 4.8 EPSS 0.22% Jun 26, 2026
CVE-2026-47207 MEDIUM

Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message

CVSS 6.5 EPSS 0.44% Jun 26, 2026

Showing 1 to 25 CVEs · page 1 (more available)