Envoyproxy

Envoy

126 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 01.07.2024 21:15:04
  • Zuletzt bearbeitet 02.09.2025 20:30:37

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is configured with cookie attributes. Note that this vulnerability has bee...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:16:09

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:18:30

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker can exploit this vulnerability by sending a request without `FIN`, ...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:18:30

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception wo...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 04.06.2024 21:15:34
  • Zuletzt bearbeitet 21.11.2024 09:18:30

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.

  • EPSS 0.36%
  • Veröffentlicht 04.06.2024 21:15:33
  • Zuletzt bearbeitet 21.11.2024 08:57:30

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#s...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 04.06.2024 21:15:33
  • Zuletzt bearbeitet 21.11.2024 09:16:08

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused by QUICHE continuing push request headers after `StopRea...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 04.06.2024 21:15:33
  • Zuletzt bearbeitet 21.11.2024 09:16:08

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` implementation.

  • EPSS 0.69%
  • Veröffentlicht 18.04.2024 15:15:30
  • Zuletzt bearbeitet 04.09.2025 19:39:08

Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process....

  • EPSS 87.81%
  • Veröffentlicht 04.04.2024 20:15:08
  • Zuletzt bearbeitet 04.11.2025 19:17:06

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the...