VYPR

Vendor CVEs

Envoy

All CVEs

65 total · sorted by risk
  • CVE-2026-47205modJun 26, 2026
    risk 0.19cvss epss 0.00

    Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides

  • CVE-2018-17500LowMar 21, 2019
    risk 0.19cvss 2.9epss 0.00

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.

  • CVE-2018-17499LowMar 21, 2019
    risk 0.19cvss 2.9epss 0.00

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.

  • CVE-2024-27919HigApr 4, 2024
    risk 0.07cvss 7.5epss 0.87

    Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an…

  • CVE-2024-32475HigApr 18, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process. Envoy does not gracefully…

  • CVE-2024-23325HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a…

  • CVE-2024-23324HigFeb 9, 2024
    risk 0.00cvss 8.6epss 0.01

    Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue…

  • CVE-2024-23322HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: 1. hedge_on_per_try_timeout is enabled, 2. per_try_idle_timeout is enabled (it can only be done in…

  • CVE-2022-29226CriJun 9, 2022
    risk 0.00cvss 10.0epss 0.01

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the…

  • CVE-2022-29224MedJun 9, 2022
    risk 0.00cvss 5.9epss 0.01

    Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can “hold”…

  • CVE-2022-23606MedFeb 22, 2022
    risk 0.00cvss 4.4epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections established to endpoints in that cluster are disconnected. A recursion was introduced in the procedure of…

  • CVE-2022-21655HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround…

  • CVE-2021-43826HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the…

  • CVE-2021-43824HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only…

  • CVE-2021-21378HigMar 11, 2021
    risk 0.00cvss 8.2epss 0.02

    Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the…

Page 2 of 2