VendorsEnvoy Proxyenvoyany version
Vulnerabilities

Envoy Proxy Envoyproxy Envoy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

101CVEs
CVE-2020-25018
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
Published 2020-10-01 · Modified
7.5EPSS 0.011
CVE-2021-43826
Crash when tunneling TCP over HTTP in Envoy
Published 2022-02-22 · Modified
7.5EPSS 0.011
CVE-2021-43824
Null pointer dereference in envoy
Published 2022-02-22 · Modified
7.5EPSS 0.011
CVE-2026-47774
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
Published 2026-06-17 · Analyzed
7.5EPSS 0.011
CVE-2021-43825
Use-after-free in Envoy
Published 2022-02-22 · Modified
7.5EPSS 0.009
CVE-2023-27496
Envoy may crash when a redirect url without a state param is received in the oauth filter
Published 2023-04-04 · Modified
7.5EPSS 0.008
CVE-2024-23325
Envoy crashes when using an address type that isn’t supported by the OS
Published 2024-02-09 · Modified
7.5EPSS 0.008
CVE-2024-53270
HTTP/1: sending overload crashes when the request is reset beforehand in envoy
Published 2024-12-18 · Analyzed
7.5EPSS 0.007
CVE-2024-23327
Crash in proxy protocol when command type of LOCAL in Envoy
Published 2024-02-09 · Modified
7.5EPSS 0.007
CVE-2024-32974
Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-32975
Envoy crashes in QuicheDataReader::PeekVarInt62Length()
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-32475
Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
Published 2024-04-18 · Analyzed
7.5EPSS 0.007
CVE-2024-32976
Envoy can enter an endless loop while decompressing Brotli data with extra input
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2024-53269
Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy
Published 2024-12-18 · Analyzed
7.5EPSS 0.007
CVE-2024-23322
Envoy crashes when idle and request per try timeout occur within the backoff interval
Published 2024-02-09 · Modified
7.5EPSS 0.007
CVE-2024-34363
Envoy can crash due to uncaught nlohmann JSON exception
Published 2024-06-04 · Modified
7.5EPSS 0.007
CVE-2026-47220
Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
Published 2026-06-26 · Modified
7.5EPSS 0.007
CVE-2023-35943
Envoy vulnerable to CORS filter segfault when origin header is removed
Published 2023-07-25 · Modified
7.5EPSS 0.007
CVE-2024-45810
Envoy crashes for LocalReply in http async client
Published 2024-09-19 · Analyzed
7.5EPSS 0.006
CVE-2026-48706
Envoy Heap Buffer Overflow in TcpStatsdSink
Published 2026-06-26 · Analyzed
7.5EPSS 0.006
CVE-2026-48042
Envoy: Stack overflow in destructor of highly nested JSON
Published 2026-06-26 · Analyzed
7.5EPSS 0.006
CVE-2024-45807
oghttp2 crash on OnBeginHeadersForStream in envoy
Published 2024-09-19 · Analyzed
7.5EPSS 0.005
CVE-2026-48044
Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
Published 2026-06-26 · Analyzed
7.5EPSS 0.005
CVE-2025-54588
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
Published 2025-09-02 · Analyzed
7.5EPSS 0.005
CVE-2026-26310
Crash for scoped ip address in Envoy during DNS
Published 2026-03-10 · Analyzed
7.5EPSS 0.005
CVE-2025-62409
Envoy allows large requests and responses to cause TCP connection pool crash
Published 2025-10-16 · Analyzed
7.5EPSS 0.005
CVE-2026-47204
Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
Published 2026-06-26 · Modified
7.5EPSS 0.004
CVE-2026-47221
Envoy: Null pointer deref in internal redirects
Published 2026-06-26 · Analyzed
7.5EPSS 0.004
CVE-2025-30157
Envoy crashes when HTTP ext_proc processes local replies
Published 2025-03-21 · Analyzed
7.5EPSS 0.004
CVE-2025-62504
Envoy Lua filter use-after-free when oversized rewritten response body causes crash
Published 2025-10-16 · Analyzed
7.5EPSS 0.004
CVE-2026-48497
Envoy: Abnormal process termination in DNS UDP filter
Published 2026-06-26 · Analyzed
7.5EPSS 0.004
CVE-2024-45809
Jwt filter crash in the clear route cache with remote JWKs in envoy
Published 2024-09-19 · Analyzed
7.5EPSS 0.004
CVE-2026-26330
Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Published 2026-03-10 · Analyzed
7.5EPSS 0.004
CVE-2026-48743
Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
Published 2026-06-26 · Analyzed
7.5EPSS 0.003
CVE-2022-21656
X.509 subjectAltName matching bypass in Envoy
Published 2022-02-22 · Modified
7.4EPSS 0.007
CVE-2024-53271
HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy
Published 2024-12-18 · Analyzed
7.1EPSS 0.006
CVE-2025-66220
Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Published 2025-12-03 · Analyzed
7.1EPSS 0.002
CVE-2022-21657
X.509 Extended Key Usage and Trust Purposes bypass in Envoy
Published 2022-02-22 · Modified
6.8EPSS 0.005
CVE-2026-47775
Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
Published 2026-06-26 · Analyzed
6.8EPSS 0.002
CVE-2022-23606
Crash when a cluster is deleted in Envoy
Published 2022-02-22 · Modified
6.5EPSS 0.010
← Prev2 / 3Next →