CVE-2026-47221
- EPSS 0.33%
- Veröffentlicht 26.06.2026 17:35:29
- Zuletzt bearbeitet 27.06.2026 20:17:07
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vulnerability when handling HTTP 303 (See Other) inter...
CVE-2026-48743
- EPSS 0.22%
- Veröffentlicht 26.06.2026 17:34:22
- Zuletzt bearbeitet 29.06.2026 18:27:36
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-o...
CVE-2026-48497
- EPSS 0.23%
- Veröffentlicht 26.06.2026 17:32:58
- Zuletzt bearbeitet 29.06.2026 18:36:40
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or ...
CVE-2026-48044
- EPSS 0.32%
- Veröffentlicht 26.06.2026 17:31:37
- Zuletzt bearbeitet 29.06.2026 18:40:43
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). Whe...
CVE-2026-48042
- EPSS 0.37%
- Veröffentlicht 26.06.2026 17:29:14
- Zuletzt bearbeitet 29.06.2026 18:42:17
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerabilit...
CVE-2026-47778
- EPSS 0.18%
- Veröffentlicht 26.06.2026 17:27:57
- Zuletzt bearbeitet 29.06.2026 18:49:25
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is ...
CVE-2026-47775
- EPSS 0.16%
- Veröffentlicht 26.06.2026 17:23:51
- Zuletzt bearbeitet 29.06.2026 18:10:33
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEA...
CVE-2026-47774
- EPSS 0.97%
- Veröffentlicht 17.06.2026 16:58:36
- Zuletzt bearbeitet 20.07.2026 12:19:35
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to t...
CVE-2026-26330
- EPSS 0.32%
- Veröffentlicht 10.03.2026 19:19:52
- Zuletzt bearbeitet 11.03.2026 15:57:32
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the response phase lim...
CVE-2026-26311
- EPSS 0.34%
- Veröffentlicht 10.03.2026 19:14:41
- Zuletzt bearbeitet 11.03.2026 16:03:58
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue creates a "Use-Af...