Skip to main content

Vendor archive

envoyproxy CVEs

Beta · best-effort

113 CVEs tagged to vendor envoyproxy3 Critical, 59 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2022-21656

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validatio…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21655

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured wi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21654

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their defaul…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43826

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43825

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further processing of request or response da…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43824

Published Feb 22, 2022

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39206

Published Sep 9, 2021

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. Th…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39204

Published Sep 9, 2021

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39162

Published Sep 9, 2021

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32781

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated respons…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32780

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitions a H/2 connection to the CLO…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32779

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' e…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32778

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedure for resetting a HTTP/2 stre…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32777

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request h…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29492

Published May 28, 2021

Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29258

Published May 20, 2021

An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28683

Published May 20, 2021

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28682

Published May 20, 2021

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21378

Published Mar 11, 2021

Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35471

Published Dec 15, 2020

Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35470

Published Dec 15, 2020

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situ…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25018

Published Oct 1, 2020

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25017

Published Oct 1, 2020

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing o…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15104

Published Jul 14, 2020

In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multip…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8663

Published Jul 1, 2020

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 113 CVEsPage 4 of 5