Envoy Proxy Envoy是Envoy Proxy团队的应用网关。 Envoy Proxy Envoy 1.23.0版本至1.35.11之前版本、1.36.0版本至1.36.7之前版本、1.37.0版本至1.37.3之前版本和1.38.0版本至1.38.1之前版本存在资源管理错误漏洞,该漏洞源于zstd解压器实现问题,处理特制的高度压缩zstd有效载荷可能导致大量内存分配,攻击者利用此漏洞可造成严重内存耗尽,导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| envoyproxy | envoy | >= 1.38.0, < 1.38.1 |
affected |
>= 1.37.0, < 1.37.3 |
affected | ||
>= 1.36.0, < 1.36.7 |
affected | ||
>= 1.23.0, < 1.35.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | >= 1.38.0, < 1.38.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48743 | 7.5 HIGH | Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Le |
| CVE-2026-48042 | 7.5 HIGH | Envoy: Stack overflow in destructor of highly nested JSON |
| CVE-2026-47220 | 7.5 HIGH | Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format |
| CVE-2026-47775 | 6.8 MEDIUM | Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption |
| CVE-2026-47204 | 6.5 MEDIUM | Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes |
| CVE-2026-47207 | 6.5 MEDIUM | Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message |
| CVE-2026-47221 | 5.9 MEDIUM | Envoy: Null pointer deref in internal redirects |
| CVE-2026-48497 | 5.9 MEDIUM | Envoy: Abnormal process termination in DNS UDP filter |
| CVE-2026-48706 | 5.9 MEDIUM | Envoy Heap Buffer Overflow in TcpStatsdSink |
| CVE-2026-47205 | 5.9 MEDIUM | Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides |
| CVE-2026-48090 | 5.9 MEDIUM | Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash r |
| CVE-2026-47692 | 4.8 MEDIUM | Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-con |
| CVE-2026-47778 | 4.4 MEDIUM | Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (A |
No comments yet