Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic nam
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| envoyproxy | envoy | < 1.36.10 |
affected |
>= 1.37.0, < 1.37.6 |
affected | ||
>= 1.38.0, < 1.38.4 |
affected | ||
>= 1.39.0, < 1.39.1 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | envoy | < 1.36.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73550 | 7.5 HIGH | Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy |
| CVE-2026-73512 | 7.5 HIGH | Envoy: use-after-free in QUIC on internal redirects |
| CVE-2026-73553 | 7.5 HIGH | Envoy: RBAC Authorization Bypass via Path Parameters |
| CVE-2026-73513 | 7.5 HIGH | Envoy: oghttp2 upstream trailers incorrect handling |
| CVE-2026-73548 | 7.5 HIGH | Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's |
| CVE-2026-73547 | 7.5 HIGH | Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check |
| CVE-2026-73552 | 7.5 HIGH | Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values |
| CVE-2026-48521 | 5.9 MEDIUM | Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocate |
| CVE-2026-50572 | 5.9 MEDIUM | Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault |
| CVE-2026-73511 | 5.3 MEDIUM | Envoy: Potential path-matching/authentication bypass when using Envoy in combination with |
| CVE-2026-73549 | 5.3 MEDIUM | Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IP |
| CVE-2026-73551 | 5.3 MEDIUM | Envoy: Path normalization does not handle dot and dotdot segments with parameters |
No comments yet