CVE-2026-73511
- EPSS 0.55%
- Veröffentlicht 21.09.2026 20:20:26
- Zuletzt bearbeitet 05.10.2026 14:35:20
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix para...
CVE-2026-73553
- EPSS 0.52%
- Veröffentlicht 21.09.2026 20:18:47
- Zuletzt bearbeitet 05.10.2026 14:08:59
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching b...
CVE-2026-73551
- EPSS 0.55%
- Veröffentlicht 21.09.2026 20:17:02
- Zuletzt bearbeitet 05.10.2026 14:06:32
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A req...
CVE-2026-73546
- EPSS 0.6%
- Veröffentlicht 21.09.2026 19:53:21
- Zuletzt bearbeitet 05.10.2026 13:40:45
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits sta...
CVE-2026-73512
- EPSS 0.83%
- Veröffentlicht 21.09.2026 19:51:23
- Zuletzt bearbeitet 05.10.2026 14:12:31
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, in...
CVE-2026-73550
- EPSS 0.88%
- Veröffentlicht 21.09.2026 19:49:28
- Zuletzt bearbeitet 05.10.2026 14:07:45
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The disc...
CVE-2026-73547
- EPSS 0.83%
- Veröffentlicht 21.09.2026 19:47:54
- Zuletzt bearbeitet 06.10.2026 15:34:36
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set o...
CVE-2026-48521
- EPSS 0.7%
- Veröffentlicht 21.09.2026 19:44:15
- Zuletzt bearbeitet 05.10.2026 14:09:45
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selecting an HTTP/3 c...
CVE-2026-73549
- EPSS 0.61%
- Veröffentlicht 21.09.2026 19:42:48
- Zuletzt bearbeitet 05.10.2026 14:09:22
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through a...
CVE-2026-73513
- EPSS 0.72%
- Veröffentlicht 21.09.2026 19:40:49
- Zuletzt bearbeitet 05.10.2026 14:08:23
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy com...