Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters fro
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| envoyproxy | envoy | < 1.36.10 |
affected |
>= 1.37.0, < 1.37.6 |
affected | ||
>= 1.38.0, < 1.38.4 |
affected | ||
>= 1.39.0, < 1.39.1 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | < 1.36.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73550 | 7.5 HIGH | Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy |
| CVE-2026-73512 | 7.5 HIGH | Envoy: use-after-free in QUIC on internal redirects |
| CVE-2026-73553 | 7.5 HIGH | Envoy: RBAC Authorization Bypass via Path Parameters |
| CVE-2026-73513 | 7.5 HIGH | Envoy: oghttp2 upstream trailers incorrect handling |
| CVE-2026-73548 | 7.5 HIGH | Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's |
| CVE-2026-73547 | 7.5 HIGH | Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check |
| CVE-2026-73552 | 7.5 HIGH | Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values |
| CVE-2026-73546 | 7.4 HIGH | Envoy: Stored XSS in Admin Stats Interface (/stats?format=html) |
| CVE-2026-48521 | 5.9 MEDIUM | Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocate |
| CVE-2026-50572 | 5.9 MEDIUM | Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault |
| CVE-2026-73549 | 5.3 MEDIUM | Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IP |
| CVE-2026-73551 | 5.3 MEDIUM | Envoy: Path normalization does not handle dot and dotdot segments with parameters |
No comments yet