VendorsEnvoy Proxyenvoyall versions
Vulnerabilities

Envoy Proxy Envoyproxy Envoy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

110CVEs
CVE-2022-29225
Zip bomb vulnerability in Envoy
Published 2022-06-09 · Modified
7.5EPSS 0.016
CVE-2020-8663
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
Published 2020-07-01 · Modified
7.5EPSS 0.015
CVE-2020-12605
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.
Published 2020-07-01 · Modified
7.5EPSS 0.014
CVE-2020-12603
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.
Published 2020-07-01 · Modified
7.5EPSS 0.014
CVE-2023-35945
Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec
Published 2023-07-13 · Modified
7.5EPSS 0.013
CVE-2022-29228
Reachable assertion in Envoy
Published 2022-06-09 · Modified
7.5EPSS 0.012
CVE-2021-32778
Excessive CPU utilization when closing HTTP/2 streams
Published 2021-08-24 · Modified
7.5EPSS 0.012
CVE-2022-29227
Use after free in Envoy
Published 2022-06-09 · Modified
7.5EPSS 0.012
CVE-2022-21655
Incorrect handling of internal redirects results in crash in Envoy
Published 2022-02-22 · Modified
7.5EPSS 0.011
CVE-2020-25018
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
Published 2020-10-01 · Modified
7.5EPSS 0.011
CVE-2021-43824
Null pointer dereference in envoy
Published 2022-02-22 · Modified
7.5EPSS 0.011
CVE-2021-43826
Crash when tunneling TCP over HTTP in Envoy
Published 2022-02-22 · Modified
7.5EPSS 0.011
CVE-2026-47774
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
Published 2026-06-17 · Analyzed
7.5EPSS 0.011
CVE-2021-43825
Use-after-free in Envoy
Published 2022-02-22 · Modified
7.5EPSS 0.009
CVE-2023-27496
Envoy may crash when a redirect url without a state param is received in the oauth filter
Published 2023-04-04 · Modified
7.5EPSS 0.008
CVE-2024-23325
Envoy crashes when using an address type that isn’t supported by the OS
Published 2024-02-09 · Modified
7.5EPSS 0.008
CVE-2024-53270
HTTP/1: sending overload crashes when the request is reset beforehand in envoy
Published 2024-12-18 · Analyzed
7.5EPSS 0.007
CVE-2024-23327
Crash in proxy protocol when command type of LOCAL in Envoy
Published 2024-02-09 · Modified
7.5EPSS 0.007
CVE-2024-32974
Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-32975
Envoy crashes in QuicheDataReader::PeekVarInt62Length()
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-32475
Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
Published 2024-04-18 · Analyzed
7.5EPSS 0.007
CVE-2024-32976
Envoy can enter an endless loop while decompressing Brotli data with extra input
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-53269
Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy
Published 2024-12-18 · Analyzed
7.5EPSS 0.007
CVE-2024-23322
Envoy crashes when idle and request per try timeout occur within the backoff interval
Published 2024-02-09 · Modified
7.5EPSS 0.007
CVE-2024-34363
Envoy can crash due to uncaught nlohmann JSON exception
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2026-47220
Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
Published 2026-06-26 · Modified
7.5EPSS 0.007
CVE-2023-35943
Envoy vulnerable to CORS filter segfault when origin header is removed
Published 2023-07-25 · Modified
7.5EPSS 0.007
CVE-2024-45810
Envoy crashes for LocalReply in http async client
Published 2024-09-19 · Analyzed
7.5EPSS 0.006
CVE-2026-48706
Envoy Heap Buffer Overflow in TcpStatsdSink
Published 2026-06-26 · Analyzed
7.5EPSS 0.006
CVE-2026-48042
Envoy: Stack overflow in destructor of highly nested JSON
Published 2026-06-26 · Analyzed
7.5EPSS 0.006
CVE-2024-45807
oghttp2 crash on OnBeginHeadersForStream in envoy
Published 2024-09-19 · Analyzed
7.5EPSS 0.005
CVE-2026-48044
Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
Published 2026-06-26 · Analyzed
7.5EPSS 0.005
CVE-2025-54588
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
Published 2025-09-02 · Analyzed
7.5EPSS 0.005
CVE-2026-26310
Crash for scoped ip address in Envoy during DNS
Published 2026-03-10 · Analyzed
7.5EPSS 0.005
CVE-2025-62409
Envoy allows large requests and responses to cause TCP connection pool crash
Published 2025-10-16 · Analyzed
7.5EPSS 0.005
CVE-2026-47204
Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
Published 2026-06-26 · Modified
7.5EPSS 0.004
CVE-2026-47221
Envoy: Null pointer deref in internal redirects
Published 2026-06-26 · Analyzed
7.5EPSS 0.004
CVE-2025-30157
Envoy crashes when HTTP ext_proc processes local replies
Published 2025-03-21 · Analyzed
7.5EPSS 0.004
CVE-2025-62504
Envoy Lua filter use-after-free when oversized rewritten response body causes crash
Published 2025-10-16 · Analyzed
7.5EPSS 0.004
CVE-2026-48497
Envoy: Abnormal process termination in DNS UDP filter
Published 2026-06-26 · Analyzed
7.5EPSS 0.004
← Prev2 / 3Next →