CVE Browser
Envoy: RBAC Authorization Bypass via Path Parameters
Envoy: Path normalization does not handle dot and dotdot segments with parameters
Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache…
Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values
Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy
Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters
Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool
Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)
Envoy: oghttp2 upstream trailers incorrect handling
Envoy: use-after-free in QUIC on internal redirects
Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault
Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null
Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check
Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
Showing 1 to 25 CVEs · page 1 (more available)