CVE-2026-73552
- EPSS 0.67%
- Veröffentlicht 21.09.2026 19:37:20
- Zuletzt bearbeitet 05.10.2026 14:35:24
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semant...
CVE-2026-73548
- EPSS 0.67%
- Veröffentlicht 21.09.2026 19:35:15
- Zuletzt bearbeitet 05.10.2026 14:19:45
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthent...
CVE-2026-50572
- EPSS 0.68%
- Veröffentlicht 21.09.2026 19:32:00
- Zuletzt bearbeitet 05.10.2026 14:12:02
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is rejected. When RawH...
CVE-2026-48090
- EPSS 0.43%
- Veröffentlicht 26.06.2026 18:03:05
- Zuletzt bearbeitet 08.07.2026 20:16:50
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream...
CVE-2026-47220
- EPSS 0.42%
- Veröffentlicht 26.06.2026 18:02:17
- Zuletzt bearbeitet 15.07.2026 02:22:19
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST,...
CVE-2026-47205
- EPSS 0.27%
- Veröffentlicht 26.06.2026 18:01:07
- Zuletzt bearbeitet 29.06.2026 18:21:30
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter w...
CVE-2026-47692
- EPSS 0.14%
- Veröffentlicht 26.06.2026 17:59:38
- Zuletzt bearbeitet 27.06.2026 20:09:48
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch b...
CVE-2026-47207
- EPSS 0.29%
- Veröffentlicht 26.06.2026 17:52:27
- Zuletzt bearbeitet 27.06.2026 20:20:41
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted Proce...
CVE-2026-48706
- EPSS 0.38%
- Veröffentlicht 26.06.2026 17:38:23
- Zuletzt bearbeitet 29.06.2026 18:34:15
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can...
CVE-2026-47204
- EPSS 0.3%
- Veröffentlicht 26.06.2026 17:37:17
- Zuletzt bearbeitet 29.06.2026 14:16:53
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null pointer dereference / segfault) when a Connect protoc...