Envoyproxy

Envoy

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.12.2024 20:15:24
  • Zuletzt bearbeitet 28.08.2025 14:41:52

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.12.2024 20:15:24
  • Zuletzt bearbeitet 04.09.2025 13:47:17

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 20.09.2024 00:15:03
  • Zuletzt bearbeitet 24.09.2024 19:48:22

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and requests mirroring. The http async client will crash du...

  • EPSS 0.1%
  • Veröffentlicht 20.09.2024 00:15:02
  • Zuletzt bearbeitet 24.09.2024 20:12:24

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remote JWKs are used, which requires async header processing; 2. clear_route...

  • EPSS 0.05%
  • Veröffentlicht 20.09.2024 00:15:02
  • Zuletzt bearbeitet 25.09.2024 17:18:38

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for ...

  • EPSS 0.08%
  • Veröffentlicht 20.09.2024 00:15:02
  • Zuletzt bearbeitet 25.09.2024 17:12:38

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the `oghttp2` by...

  • EPSS 0.17%
  • Veröffentlicht 20.09.2024 00:15:02
  • Zuletzt bearbeitet 15.10.2024 16:03:44

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or other malicious actions within the mesh. This iss...

  • EPSS 0.05%
  • Veröffentlicht 01.07.2024 21:15:04
  • Zuletzt bearbeitet 02.09.2025 20:30:37

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is configured with cookie attributes. Note that this vulnerability has bee...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:16:09

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:18:30

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker can exploit this vulnerability by sending a request without `FIN`, ...