Skip to main content

Vendor archive

envoyproxy CVEs

Beta · best-effort

113 CVEs tagged to vendor envoyproxy3 Critical, 59 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2025-62409

Published Oct 16, 2025

Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP connection pool…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55162

Published Sep 3, 2025

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, 1.34.0 throug…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54588

Published Sep 3, 2025

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a use-after-free…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46821

Published May 7, 2025

Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI template matcher incorrectly excludes the `*` character from a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30157

Published Mar 21, 2025

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25294

Published Mar 6, 2025

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-24030

Published Jan 23, 2025

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a pa…

CVSS 7.1 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2024-53271

Published Dec 18, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstrea…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53270

Published Dec 18, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_poi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53269

Published Dec 18, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plan…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45810

Published Sep 20, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websock…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45809

Published Sep 20, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remot…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45808

Published Sep 20, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45807

Published Sep 20, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream manageme…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45806

Published Sep 20, 2024

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39305

Published Jul 1, 2024

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route hash policy is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34364

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34363

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34362

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attac…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32976

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32975

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequ…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32974

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-aft…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23326

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade h…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32475

Published Apr 18, 2024

Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30255

Published Apr 4, 2024

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhausti…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 26-50 of 113 CVEsPage 2 of 5