VYPR
High severity8.8NVD Advisory· Published Dec 15, 2020· Updated Jun 17, 2026

CVE-2020-35470

CVE-2020-35470

Description

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Envoyproxy/Envoy2 versions
    cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*range: <1.16.1
    • (no CPE)range: <1.16.1
  • Envoy/envoycpe-rescue
  • osv-coords
    Range: < 1.16.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.

CVE-2020-35470 · High · VYPR