CVE-2025-55162
- EPSS 0.01%
- Veröffentlicht 03.09.2025 19:51:51
- Zuletzt bearbeitet 08.09.2025 18:42:05
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, 1.34.0 through 1.34.4 and 1.35.0, insufficient Session Expiration in the Envoy OAuth...
CVE-2025-54588
- EPSS 0.01%
- Veröffentlicht 02.09.2025 23:39:07
- Zuletzt bearbeitet 08.09.2025 15:19:04
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a use-after-free (UAF) vulnerability in the DNS cache, causing abnormal process termina...
CVE-2025-46821
- EPSS 0.01%
- Veröffentlicht 07.05.2025 21:24:07
- Zuletzt bearbeitet 03.09.2025 17:57:13
Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI template matcher incorrectly excludes the `*` character from a set of valid characters in the URI path. As a result URI path containi...
CVE-2025-30157
- EPSS 0.01%
- Veröffentlicht 21.03.2025 14:49:18
- Zuletzt bearbeitet 01.04.2025 20:22:34
Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue....
CVE-2024-53271
- EPSS 0%
- Veröffentlicht 18.12.2024 20:15:24
- Zuletzt bearbeitet 04.09.2025 14:03:45
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versi...
CVE-2024-53270
- EPSS 0.01%
- Veröffentlicht 18.12.2024 20:15:24
- Zuletzt bearbeitet 04.09.2025 13:47:17
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is ...
CVE-2024-53269
- EPSS 0.01%
- Veröffentlicht 18.12.2024 20:15:24
- Zuletzt bearbeitet 28.08.2025 14:41:52
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8...
CVE-2024-45810
- EPSS 0.05%
- Veröffentlicht 20.09.2024 00:15:03
- Zuletzt bearbeitet 24.09.2024 19:48:22
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and requests mirroring. The http async client will crash du...
CVE-2024-45808
- EPSS 0.03%
- Veröffentlicht 20.09.2024 00:15:02
- Zuletzt bearbeitet 25.09.2024 17:18:38
Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for ...
CVE-2024-45806
- EPSS 0.33%
- Veröffentlicht 20.09.2024 00:15:02
- Zuletzt bearbeitet 15.10.2024 16:03:44
Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or other malicious actions within the mesh. This iss...