Envoyproxy / Envoy
126 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73553 | Envoy: RBAC Authorization Bypass via Path Parameters | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-73511 | Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache… | MEDIUM | 5.3 | Sep 21, 2026 |
| CVE-2026-73549 | Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters | MEDIUM | 5.3 | Sep 21, 2026 |
| CVE-2026-73512 | Envoy: use-after-free in QUIC on internal redirects | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-50572 | Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault | MEDIUM | 5.9 | Sep 21, 2026 |
| CVE-2026-73551 | Envoy: Path normalization does not handle dot and dotdot segments with parameters | MEDIUM | 5.3 | Sep 21, 2026 |
| CVE-2026-73546 | Envoy: Stored XSS in Admin Stats Interface (/stats?format=html) | HIGH | 7.4 | Sep 21, 2026 |
| CVE-2026-73550 | Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-73547 | Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-48521 | Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null | MEDIUM | 5.9 | Sep 21, 2026 |
| CVE-2026-73513 | Envoy: oghttp2 upstream trailers incorrect handling | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-73552 | Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-73548 | Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool | HIGH | 7.5 | Sep 21, 2026 |
| CVE-2026-48090 | Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk) | MEDIUM | 5.9 | Jun 26, 2026 |
| CVE-2026-47220 | Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-47205 | Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides | MEDIUM | 5.9 | Jun 26, 2026 |
| CVE-2026-47692 | Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream | MEDIUM | 4.8 | Jun 26, 2026 |
| CVE-2026-47207 | Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message | MEDIUM | 6.5 | Jun 26, 2026 |
| CVE-2026-48706 | Envoy Heap Buffer Overflow in TcpStatsdSink | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-47204 | Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-47221 | Envoy: Null pointer deref in internal redirects | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48743 | Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48497 | Envoy: Abnormal process termination in DNS UDP filter | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48044 | Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48042 | Envoy: Stack overflow in destructor of highly nested JSON | HIGH | 7.5 | Jun 26, 2026 |
Showing 1 to 25 of 126 CVEs