Envoyproxy

Envoy

126 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 26.06.2026 17:35:29
  • Zuletzt bearbeitet 27.06.2026 20:17:07

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vulnerability when handling HTTP 303 (See Other) inter...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 26.06.2026 17:34:22
  • Zuletzt bearbeitet 29.06.2026 18:27:36

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-o...

  • EPSS 0.23%
  • Veröffentlicht 26.06.2026 17:32:58
  • Zuletzt bearbeitet 29.06.2026 18:36:40

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 26.06.2026 17:31:37
  • Zuletzt bearbeitet 29.06.2026 18:40:43

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). Whe...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 26.06.2026 17:29:14
  • Zuletzt bearbeitet 29.06.2026 18:42:17

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerabilit...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 26.06.2026 17:27:57
  • Zuletzt bearbeitet 29.06.2026 18:49:25

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is ...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.06.2026 17:23:51
  • Zuletzt bearbeitet 29.06.2026 18:10:33

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEA...

Exploit
  • EPSS 0.97%
  • Veröffentlicht 17.06.2026 16:58:36
  • Zuletzt bearbeitet 20.07.2026 12:19:35

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to t...

  • EPSS 0.32%
  • Veröffentlicht 10.03.2026 19:19:52
  • Zuletzt bearbeitet 11.03.2026 15:57:32

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the response phase lim...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 10.03.2026 19:14:41
  • Zuletzt bearbeitet 11.03.2026 16:03:58

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue creates a "Use-Af...