vciy

CVEs we hold for Envoyproxy

Records whose assigning authority named Envoyproxy as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-53719Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationenvoyproxy gateway
CVE-2026-53718Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassenvoyproxy gateway
CVE-2026-53717Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerenvoyproxy gateway
CVE-2026-53716Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limitenvoyproxy gateway
CVE-2026-53715Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lockenvoyproxy gateway
CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeenvoyproxy gateway
CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosureenvoyproxy gateway
CVE-2026-48743Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Lengthenvoyproxy envoy
CVE-2026-48706Envoy Heap Buffer Overflow in TcpStatsdSinkenvoyproxy envoy
CVE-2026-48497Envoy: Abnormal process termination in DNS UDP filterenvoyproxy envoy
CVE-2026-48090Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)envoyproxy envoy
CVE-2026-48044Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosionenvoyproxy envoy
CVE-2026-48042Envoy: Stack overflow in destructor of highly nested JSONenvoyproxy envoy
CVE-2026-47778Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)envoyproxy envoy
CVE-2026-47775Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryptionenvoyproxy envoy
CVE-2026-47774Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationenvoyproxy envoy
CVE-2026-47692Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the…envoyproxy envoy
CVE-2026-47221Envoy: Null pointer deref in internal redirectsenvoyproxy envoy
CVE-2026-47220Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log formatenvoyproxy envoy
CVE-2026-47207Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC messageenvoyproxy envoy
CVE-2026-47205Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overridesenvoyproxy envoy
CVE-2026-47204Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routesenvoyproxy envoy
CVE-2026-26330Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed…envoyproxy envoy
CVE-2026-26311Envoy HTTP: filter chain execution on reset streams causing UAF crashenvoyproxy envoy
CVE-2026-26310Crash for scoped ip address in Envoy during DNSenvoyproxy envoy
CVE-2026-26309Envoy has an off-by-one write in JsonEscaper::escapeString()envoyproxy envoy
CVE-2026-26308Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenationenvoyproxy envoy
CVE-2026-22771Envoy Extension Policy lua scripts injection causes arbitrary command executionenvoyproxy gateway
CVE-2025-66220Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an…envoyproxy envoy
CVE-2025-64763Envoy forwards early CONNECT data in TCP proxy modeenvoyproxy envoy
CVE-2025-64527Envoy crashes when JWT authentication is configured with the remote JWKS fetchingenvoyproxy envoy
CVE-2025-62504Envoy Lua filter use-after-free when oversized rewritten response body causes crashenvoyproxy envoy
CVE-2025-62409Envoy allows large requests and responses to cause TCP connection pool crashenvoyproxy envoy
CVE-2025-55162Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flagenvoyproxy envoy
CVE-2025-54588Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsenvoyproxy envoy
CVE-2025-46821Envoy vulnerable to bypass of RBAC uri_template permissionenvoyproxy envoy
CVE-2025-30157Envoy crashes when HTTP ext_proc processes local repliesenvoyproxy envoy
CVE-2025-25294Envoy Gateway Log Injection Vulnerabilityenvoyproxy gateway
CVE-2025-24030Envoy Admin Interface Exposed through prometheus metrics endpointenvoyproxy gateway
CVE-2024-53271HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoyenvoyproxy envoy
CVE-2024-53270HTTP/1: sending overload crashes when the request is reset beforehand in envoyenvoyproxy envoy
CVE-2024-53269Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoyenvoyproxy envoy
CVE-2024-45810Envoy crashes for LocalReply in http async clientenvoyproxy envoy
CVE-2024-45809Jwt filter crash in the clear route cache with remote JWKs in envoyenvoyproxy envoy
CVE-2024-45808Malicious log injection via access logs in envoyenvoyproxy envoy
CVE-2024-45807oghttp2 crash on OnBeginHeadersForStream in envoyenvoyproxy envoy
CVE-2024-45806Potential manipulate `x-envoy` headers from external sources in envoyenvoyproxy envoy
CVE-2024-39305Envoy Proxy use after free when route hash policy is configured with cookie attributesenvoyproxy envoy
CVE-2024-34364Envoy OOM vector from HTTP async client with unbounded response buffer for mirror responseenvoyproxy envoy
CVE-2024-34363Envoy can crash due to uncaught nlohmann JSON exceptionenvoyproxy envoy
CVE-2024-34362Envoy affected by a crash (use-after-free) in EnvoyQuicServerStreamenvoyproxy envoy
CVE-2024-32976Envoy can enter an endless loop while decompressing Brotli data with extra inputenvoyproxy envoy
CVE-2024-32975Envoy crashes in QuicheDataReader::PeekVarInt62Length()envoyproxy envoy
CVE-2024-32974Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()envoyproxy envoy
CVE-2024-32475Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytesenvoyproxy envoy
CVE-2024-30255HTTP/2: CPU exhaustion due to CONTINUATION frame floodenvoyproxy envoy
CVE-2024-27919HTTP/2: memory exhaustion due to CONTINUATION frame floodenvoyproxy envoy
CVE-2024-23327Crash in proxy protocol when command type of LOCAL in Envoyenvoyproxy envoy
CVE-2024-23326Envoy incorrectly accepts HTTP 200 response for entering upgrade modeenvoyproxy envoy
CVE-2024-23325Envoy crashes when using an address type that isn’t supported by the OSenvoyproxy envoy
CVE-2024-23324Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadataenvoyproxy envoy
CVE-2024-23323Excessive CPU usage when URI template matcher is configured using regex in Envoyenvoyproxy envoy
CVE-2024-23322Envoy crashes when idle and request per try timeout occur within the backoff intervalenvoyproxy envoy
CVE-2023-35945Envoy vulnerable to HTTP/2 memory leak in nghttp2 codecenvoyproxy envoy
CVE-2023-35944Envoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemesenvoyproxy envoy
CVE-2023-35943Envoy vulnerable to CORS filter segfault when origin header is removedenvoyproxy envoy
CVE-2023-35942Envoy's gRPC access log crash caused by the listener drainingenvoyproxy envoy
CVE-2023-35941Envoy vulnerable to OAuth2 credentials exploit with permanent validityenvoyproxy envoy
CVE-2023-27496Envoy may crash when a redirect url without a state param is received in the oauth filterenvoyproxy envoy
CVE-2023-27493Envoy doesn't escape HTTP header valuesenvoyproxy envoy
CVE-2023-27492Envoy may crash when a large request body is processed in Lua filterenvoyproxy envoy
CVE-2023-27491Envoy forwards invalid Http2/Http3 downstream headersenvoyproxy envoy
CVE-2023-27488Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.envoyproxy envoy
CVE-2023-27487Envoy client may fake the header `x-envoy-original-path`envoyproxy envoy
CVE-2022-29228Reachable assertion in Envoyenvoyproxy envoy
CVE-2022-29227Use after free in Envoyenvoyproxy envoy
CVE-2022-29226Trivial authentication bypass in Envoyenvoyproxy envoy
CVE-2022-29225Zip bomb vulnerability in Envoyenvoyproxy envoy
CVE-2022-29224Segmentation fault leading to crash in Envoyenvoyproxy envoy
CVE-2022-23606Crash when a cluster is deleted in Envoyenvoyproxy envoy
CVE-2022-21657X.509 Extended Key Usage and Trust Purposes bypass in Envoyenvoyproxy envoy
CVE-2022-21656X.509 subjectAltName matching bypass in Envoyenvoyproxy envoy
CVE-2022-21655Incorrect handling of internal redirects results in crash in Envoyenvoyproxy envoy
CVE-2022-21654Incorrect configuration handling allows TLS session re-use without re-validation in Envoyenvoyproxy envoy
CVE-2021-43826Crash when tunneling TCP over HTTP in Envoyenvoyproxy envoy
CVE-2021-43825Use-after-free in Envoyenvoyproxy envoy
CVE-2021-43824Null pointer dereference in envoyenvoyproxy envoy
CVE-2021-32781Continued processing of requests after locally generated responseenvoyproxy envoy
CVE-2021-32780Incorrect handling of H/2 GOAWAY followed by SETTINGS framesenvoyproxy envoy
CVE-2021-32779Incorrectly handling of URI '#fragment' element as part of the path elementenvoyproxy envoy
CVE-2021-32778Excessive CPU utilization when closing HTTP/2 streamsenvoyproxy envoy
CVE-2021-32777Incorrect concatenation of multiple value request headers in ext-authz extensionenvoyproxy envoy
CVE-2021-29492Bypass of path matching rules using escaped slash charactersenvoyproxy envoy
CVE-2021-21378JWT authentication bypass with unknown issuer tokenenvoyproxy envoy
CVE-2020-15104TLS Validation Vulnerability in Envoyenvoyproxy envoy

95 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.