VYPR

Bitnami package

envoy

pkg:bitnami/envoy

Vulnerabilities (101)

  • CVE-2026-48090MedJun 26, 2026
    affected >= 1.37.0, < 1.37.5fixed 1.37.5

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn do

  • CVE-2026-47220HigJun 26, 2026
    affected >= 1.37.0, < 1.37.5fixed 1.37.5

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy

  • CVE-2026-47205MedJun 26, 2026
    affected >= 1.36.0, < 1.36.9fixed 1.36.9

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter when processing per-route autho

  • CVE-2026-48743HigJun 26, 2026
    affected >= 1.35.0, < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-only close) but still carries a

  • CVE-2026-48706MedJun 26, 2026
    affected >= 1.34.0, < 1.35.13fixed 1.35.13

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionall

  • CVE-2026-48497MedJun 26, 2026
    affected < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name o

  • CVE-2026-48044HigJun 26, 2026
    affected >= 1.23.0, < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enable

  • CVE-2026-48042HigJun 26, 2026
    affected < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7,

  • CVE-2026-47778MedJun 26, 2026
    affected < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is cast to a C-style string using

  • CVE-2026-47775MedJun 26, 2026
    affected < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEAD). The /callback endpoint ret

  • CVE-2026-47692MedJun 26, 2026
    affected >= 1.34.0, < 1.35.13fixed 1.35.13

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch between bytes written and the l

  • CVE-2026-47221MedJun 26, 2026
    affected >= 1.18.0, < 1.35.13fixed 1.35.13

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vulnerability when handling HTTP 303 (See Other) internal redirects for body-less no

  • CVE-2026-47207MedJun 26, 2026
    affected >= 1.34.0, < 1.35.13fixed 1.35.13

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted ProcessingResponse messages. This c

  • CVE-2026-47204MedJun 26, 2026
    affected >= 1.26.0, < 1.35.13fixed 1.35.13

    Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null pointer dereference / segfault) when a Connect protocol request (Content-Type: appl

  • CVE-2026-47774HigJun 17, 2026
    affected < 1.35.11fixed 1.35.11

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consum

  • CVE-2026-26330MedMar 10, 2026
    affected < 1.34.13fixed 1.34.13

    Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the response phase limit request fails directly, it

  • CVE-2026-26311MedMar 10, 2026
    affected < 1.34.13fixed 1.34.13

    Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue creates a "Use-After-Free" (UAF) or state-corru

  • CVE-2026-26310MedMar 10, 2026
    affected < 1.34.13fixed 1.34.13

    Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scoped IPv6 addresses causes a crash. This utility is called in the data plane from the original_src filter and the dns filter. This vul

  • CVE-2026-26309MedMar 10, 2026
    affected < 1.34.13fixed 1.34.13

    Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds

  • CVE-2026-26308HigMar 10, 2026
    affected < 1.34.13fixed 1.34.13

    Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instea

Page 1 of 6