Envoyproxy

Envoy

126 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.67%
  • Veröffentlicht 21.09.2026 19:37:20
  • Zuletzt bearbeitet 05.10.2026 14:35:24

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semant...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 21.09.2026 19:35:15
  • Zuletzt bearbeitet 05.10.2026 14:19:45

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthent...

  • EPSS 0.68%
  • Veröffentlicht 21.09.2026 19:32:00
  • Zuletzt bearbeitet 05.10.2026 14:12:02

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is rejected. When RawH...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 26.06.2026 18:03:05
  • Zuletzt bearbeitet 08.07.2026 20:16:50

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 26.06.2026 18:02:17
  • Zuletzt bearbeitet 15.07.2026 02:22:19

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST,...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 26.06.2026 18:01:07
  • Zuletzt bearbeitet 29.06.2026 18:21:30

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter w...

  • EPSS 0.14%
  • Veröffentlicht 26.06.2026 17:59:38
  • Zuletzt bearbeitet 27.06.2026 20:09:48

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch b...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 26.06.2026 17:52:27
  • Zuletzt bearbeitet 27.06.2026 20:20:41

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted Proce...

  • EPSS 0.38%
  • Veröffentlicht 26.06.2026 17:38:23
  • Zuletzt bearbeitet 29.06.2026 18:34:15

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 26.06.2026 17:37:17
  • Zuletzt bearbeitet 29.06.2026 14:16:53

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null pointer dereference / segfault) when a Connect protoc...