VendorsEnvoy Proxyenvoyall versions
Vulnerabilities

Envoy Proxy Envoyproxy Envoy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

110CVEs
CVE-2024-45809
Jwt filter crash in the clear route cache with remote JWKs in envoy
Published 2024-09-19 · Analyzed
7.5EPSS 0.004
CVE-2026-26330
Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Published 2026-03-10 · Analyzed
7.5EPSS 0.004
CVE-2026-48743
Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
Published 2026-06-26 · Analyzed
7.5EPSS 0.003
CVE-2022-21656
X.509 subjectAltName matching bypass in Envoy
Published 2022-02-22 · Modified
7.4EPSS 0.007
CVE-2024-53271
HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy
Published 2024-12-18 · Analyzed
7.1EPSS 0.006
CVE-2025-66220
Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Published 2025-12-03 · Analyzed
7.1EPSS 0.002
CVE-2022-21657
X.509 Extended Key Usage and Trust Purposes bypass in Envoy
Published 2022-02-22 · Modified
6.8EPSS 0.005
CVE-2026-47775
Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
Published 2026-06-26 · Analyzed
6.8EPSS 0.002
CVE-2022-23606
Crash when a cluster is deleted in Envoy
Published 2022-02-22 · Modified
6.5EPSS 0.010
CVE-2023-35942
Envoy's gRPC access log crash caused by the listener draining
Published 2023-07-25 · Modified
6.5EPSS 0.009
CVE-2023-27492
Envoy may crash when a large request body is processed in Lua filter
Published 2023-04-04 · Modified
6.5EPSS 0.007
CVE-2025-64527
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Published 2025-12-03 · Analyzed
6.5EPSS 0.005
CVE-2024-34364
Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response
Published 2024-06-04 · Modified
6.5EPSS 0.005
CVE-2026-47207
Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
Published 2026-06-26 · Analyzed
6.5EPSS 0.004
CVE-2024-45806
Potential manipulate `x-envoy` headers from external sources in envoy
Published 2024-09-19 · Analyzed
6.5EPSS 0.004
CVE-2024-45808
Malicious log injection via access logs in envoy
Published 2024-09-19 · Analyzed
6.5EPSS 0.004
CVE-2022-29224
Segmentation fault leading to crash in Envoy
Published 2022-06-09 · Modified
5.9EPSS 0.010
CVE-2024-34362
Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream
Published 2024-06-04 · Modified
5.9EPSS 0.006
CVE-2026-48090
Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
Published 2026-06-26 · Modified
5.9EPSS 0.006
CVE-2026-26311
Envoy HTTP: filter chain execution on reset streams causing UAF crash
Published 2026-03-10 · Analyzed
5.9EPSS 0.005
CVE-2026-47205
Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
Published 2026-06-26 · Analyzed
5.9EPSS 0.004
CVE-2020-15104
TLS Validation Vulnerability in Envoy
Published 2020-07-14 · Modified
5.5EPSS 0.003
CVE-2020-8660
CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions in the process.
Published 2020-03-04 · Modified
5.3EPSS 0.006
CVE-2024-23323
Excessive CPU usage when URI template matcher is configured using regex in Envoy
Published 2024-02-09 · Modified
5.3EPSS 0.005
CVE-2026-26309
Envoy has an off-by-one write in JsonEscaper::escapeString()
Published 2026-03-10 · Analyzed
5.3EPSS 0.004
CVE-2025-64763
Envoy forwards early CONNECT data in TCP proxy mode
Published 2025-12-03 · Analyzed
5.3EPSS 0.003
CVE-2025-46821
Envoy vulnerable to bypass of RBAC uri_template permission
Published 2025-05-07 · Analyzed
5.3EPSS 0.003
CVE-2026-47692
Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
Published 2026-06-26 · Analyzed
4.8EPSS 0.002
CVE-2026-47778
Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
Published 2026-06-26 · Analyzed
4.4EPSS 0.002
CVE-2020-11767
Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind *.example.com. The outcome should instead be 421 Misdirected Request. Imagine a shared caching forward proxy re-using an HTTP/2 connection for a large subnet with many users. If a victim is interacting with abc.example.com, and a server (for abc.example.com) recycles the TCP connection to the forward proxy, the victim's browser may suddenly start sending sensitive data to a *.example.com server. This occurs because the forward proxy between the victim and the origin server reuses connections (which obeys the specification), but neither Istio nor Envoy corrects this by sending a 421 error. Similarly, this behavior voids the security model browsers have put in place between domains.
Published 2020-04-15 · Modified
3.1EPSS 0.018
← Prev3 / 3