Skip to main content

Vendor archive

envoyproxy CVEs

Beta · best-effort

113 CVEs tagged to vendor envoyproxy3 Critical, 59 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2020-12605

Published Jul 1, 2020

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12604

Published Jul 1, 2020

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough windo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12603

Published Jul 1, 2020

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11767

Published Apr 15, 2020

Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurr…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-8660

Published Mar 4, 2020

CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18838

Published Dec 13, 2019

An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internal…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18802

Published Dec 13, 2019

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18801

Published Dec 13, 2019

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. Thi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18836

Published Nov 11, 2019

Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy lo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15226

Published Oct 9, 2019

Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The im…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15225

Published Aug 19, 2019

In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9901

Published Apr 25, 2019

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-113 of 113 CVEsPage 5 of 5