Skip to main content

Vendor archive

envoyproxy CVEs

Beta · best-effort

113 CVEs tagged to vendor envoyproxy3 Critical, 59 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2024-27919

Published Apr 4, 2024

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-23327

Published Feb 9, 2024

Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23325

Published Feb 9, 2024

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23324

Published Feb 9, 2024

Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23323

Published Feb 9, 2024

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23322

Published Feb 9, 2024

Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: 1. hed…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35944

Published Jul 25, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some internal scheme checks are case-sen…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35943

Published Jul 25, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, the CORS filter will segfaul…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35942

Published Jul 25, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, gRPC access loggers using li…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35941

Published Jul 25, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35945

Published Jul 13, 2023

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27496

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the OAuth filter assumes that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27493

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or esc…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27492

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the Lua filter is vulnerable t…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27491

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27488

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, escalation of privileges is po…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27487

Published Apr 4, 2023

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the client may bypass JSON Web…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29228

Published Jun 9, 2022

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29227

Published Jun 9, 2022

Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of mor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29226

Published Jun 9, 2022

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29225

Published Jun 9, 2022

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29224

Published Jun 9, 2022

Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23606

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections establis…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21657

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certificates it accepts from the pe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 113 CVEsPage 3 of 5