CVEs we hold for Envoyproxy
Records whose assigning authority named Envoyproxy as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-53719Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationenvoyproxy gateway
CVE-2026-53718Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassenvoyproxy gateway
CVE-2026-53717Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerenvoyproxy gateway
CVE-2026-53716Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limitenvoyproxy gateway
CVE-2026-53715Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lockenvoyproxy gateway
CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeenvoyproxy gateway
CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosureenvoyproxy gateway
CVE-2026-48743Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Lengthenvoyproxy envoy
CVE-2026-48090Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)envoyproxy envoy
CVE-2026-48044Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosionenvoyproxy envoy
CVE-2026-47778Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)envoyproxy envoy
CVE-2026-47774Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationenvoyproxy envoy
CVE-2026-47692Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the…envoyproxy envoy
CVE-2026-47220Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log formatenvoyproxy envoy
CVE-2026-47207Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC messageenvoyproxy envoy
CVE-2026-47205Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overridesenvoyproxy envoy
CVE-2026-47204Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routesenvoyproxy envoy
CVE-2026-26330Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed…envoyproxy envoy
CVE-2026-26308Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenationenvoyproxy envoy
CVE-2026-22771Envoy Extension Policy lua scripts injection causes arbitrary command executionenvoyproxy gateway
CVE-2025-66220Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an…envoyproxy envoy
CVE-2025-64527Envoy crashes when JWT authentication is configured with the remote JWKS fetchingenvoyproxy envoy
CVE-2025-62504Envoy Lua filter use-after-free when oversized rewritten response body causes crashenvoyproxy envoy
CVE-2025-62409Envoy allows large requests and responses to cause TCP connection pool crashenvoyproxy envoy
CVE-2025-55162Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flagenvoyproxy envoy
CVE-2025-54588Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsenvoyproxy envoy
CVE-2024-53271HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoyenvoyproxy envoy
CVE-2024-53270HTTP/1: sending overload crashes when the request is reset beforehand in envoyenvoyproxy envoy
CVE-2024-53269Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoyenvoyproxy envoy
CVE-2024-39305Envoy Proxy use after free when route hash policy is configured with cookie attributesenvoyproxy envoy
CVE-2024-34364Envoy OOM vector from HTTP async client with unbounded response buffer for mirror responseenvoyproxy envoy
CVE-2024-32976Envoy can enter an endless loop while decompressing Brotli data with extra inputenvoyproxy envoy
CVE-2024-32974Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()envoyproxy envoy
CVE-2024-32475Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytesenvoyproxy envoy
CVE-2024-23325Envoy crashes when using an address type that isn’t supported by the OSenvoyproxy envoy
CVE-2024-23324Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadataenvoyproxy envoy
CVE-2024-23323Excessive CPU usage when URI template matcher is configured using regex in Envoyenvoyproxy envoy
CVE-2024-23322Envoy crashes when idle and request per try timeout occur within the backoff intervalenvoyproxy envoy
CVE-2023-35944Envoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemesenvoyproxy envoy
CVE-2023-35943Envoy vulnerable to CORS filter segfault when origin header is removedenvoyproxy envoy
CVE-2023-35941Envoy vulnerable to OAuth2 credentials exploit with permanent validityenvoyproxy envoy
CVE-2023-27496Envoy may crash when a redirect url without a state param is received in the oauth filterenvoyproxy envoy
CVE-2023-27488Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.envoyproxy envoy
CVE-2022-21654Incorrect configuration handling allows TLS session re-use without re-validation in Envoyenvoyproxy envoy
CVE-2021-32779Incorrectly handling of URI '#fragment' element as part of the path elementenvoyproxy envoy
CVE-2021-32777Incorrect concatenation of multiple value request headers in ext-authz extensionenvoyproxy envoy
95 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.