VendorsEnvoy Proxyenvoy1.37.0
Vulnerabilities

Envoy Proxy Envoyproxy Envoy 1.37.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-26308
Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation
Published 2026-03-10 · Analyzed
8.2EPSS 0.003
CVE-2026-26310
Crash for scoped ip address in Envoy during DNS
Published 2026-03-10 · Analyzed
7.5EPSS 0.005
CVE-2026-26330
Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Published 2026-03-10 · Analyzed
7.5EPSS 0.004
CVE-2026-26311
Envoy HTTP: filter chain execution on reset streams causing UAF crash
Published 2026-03-10 · Analyzed
5.9EPSS 0.005
CVE-2026-26309
Envoy has an off-by-one write in JsonEscaper::escapeString()
Published 2026-03-10 · Analyzed
5.3EPSS 0.004