Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

envoy — Vulnerabilities & Security Advisories 105

All 105 CVE vulnerabilities found in envoy, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Envoy proxy, a high-performance edge and service proxy developed by the Envoy Proxy Project. It collects a comprehensive set of security defects, including memory corruption, logic errors, and denial-of-service triggers, covering advisories published over the past five years. Use this aggregation to track how the vendor has addressed historical issues, understand the prevalence of specific weakness classes, and review the complete vulnerability history for the Envoy product to assess its current security posture.

Vendor: envoyproxy

CVE ID Title CVSS Severity Published
CVE-2026-73511 Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat) CWE-289 5.3 Medium 2026-09-21
CVE-2026-73553 Envoy: RBAC Authorization Bypass via Path Parameters CWE-436 7.5 High 2026-09-21
CVE-2026-73551 Envoy: Path normalization does not handle dot and dotdot segments with parameters CWE-647 5.3 Medium 2026-09-21
CVE-2026-73546 Envoy: Stored XSS in Admin Stats Interface (/stats?format=html) CWE-79 7.4 High 2026-09-21
CVE-2026-73512 Envoy: use-after-free in QUIC on internal redirects CWE-416 7.5 High 2026-09-21
CVE-2026-73550 Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy CWE-401 7.5 High 2026-09-21
CVE-2026-73547 Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check CWE-20 7.5 High 2026-09-21
CVE-2026-48521 Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null CWE-476 5.9 Medium 2026-09-21
CVE-2026-73549 Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters CWE-754 5.3 Medium 2026-09-21
CVE-2026-73513 Envoy: oghttp2 upstream trailers incorrect handling CWE-20 7.5 High 2026-09-21
CVE-2026-73552 Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values CWE-20 7.5 High 2026-09-21
CVE-2026-73548 Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool CWE-444 7.5 High 2026-09-21
CVE-2026-50572 Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault CWE-416 5.9 Medium 2026-09-21
CVE-2026-48090 Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk) CWE-416 5.9 Medium 2026-06-26
CVE-2026-47220 Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format CWE-476 7.5 High 2026-06-26
CVE-2026-47205 Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides CWE-416 5.9 Medium 2026-06-26
CVE-2026-47692 Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream CWE-130 4.8 Medium 2026-06-26
CVE-2026-47207 Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message CWE-416 6.5 Medium 2026-06-26
CVE-2026-48706 Envoy Heap Buffer Overflow in TcpStatsdSink CWE-120 5.9 Medium 2026-06-26
CVE-2026-47204 Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes CWE-476 6.5 Medium 2026-06-26
CVE-2026-47221 Envoy: Null pointer deref in internal redirects CWE-476 5.9 Medium 2026-06-26
CVE-2026-48743 Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length CWE-444 7.5 High 2026-06-26
CVE-2026-48497 Envoy: Abnormal process termination in DNS UDP filter CWE-480 5.9 Medium 2026-06-26
CVE-2026-48044 Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion CWE-409 7.5 High 2026-06-26
CVE-2026-48042 Envoy: Stack overflow in destructor of highly nested JSON CWE-1124 7.5 High 2026-06-26
CVE-2026-47778 Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass) CWE-158 4.4 Medium 2026-06-26
CVE-2026-47775 Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption CWE-209 6.8 Medium 2026-06-26
CVE-2026-47774 Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification CWE-405 7.5 High 2026-06-17
CVE-2026-6994 Envoy Query Parameter header_mutation.cc params.add injection CWE-74 6.3 Medium 2026-04-25
CVE-2026-26330 Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly CWE-416 5.3 Medium 2026-03-10

All 105 known CVE vulnerabilities affecting envoy with full Chinese analysis, references, and POCs where available.