Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

envoy — Vulnerabilities & Security Advisories 105

All 105 CVE vulnerabilities found in envoy, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Envoy proxy, a high-performance edge and service proxy developed by the Envoy Proxy Project. It collects a comprehensive set of security defects, including memory corruption, logic errors, and denial-of-service triggers, covering advisories published over the past five years. Use this aggregation to track how the vendor has addressed historical issues, understand the prevalence of specific weakness classes, and review the complete vulnerability history for the Envoy product to assess its current security posture.

Vendor: envoyproxy

CVE ID Title CVSS Severity Published
CVE-2021-43825 Use-after-free in Envoy CWE-416 6.1 Medium 2022-02-22
CVE-2022-21655 Incorrect handling of internal redirects results in crash in Envoy CWE-670 7.5 High 2022-02-22
CVE-2022-21654 Incorrect configuration handling allows TLS session re-use without re-validation in Envoy CWE-295 7.4 High 2022-02-22
CVE-2022-21657 X.509 Extended Key Usage and Trust Purposes bypass in Envoy CWE-295 6.8 Medium 2022-02-22
CVE-2022-21656 X.509 subjectAltName matching bypass in Envoy CWE-295 7.4 High 2022-02-22
CVE-2022-23606 Crash when a cluster is deleted in Envoy CWE-674 4.4 Medium 2022-02-22
CVE-2021-43824 Null pointer dereference in envoy CWE-476 7.5 High 2022-02-22
CVE-2021-32780 Incorrect handling of H/2 GOAWAY followed by SETTINGS frames CWE-754 8.6 High 2021-08-24
CVE-2021-32781 Continued processing of requests after locally generated response CWE-416 8.6 High 2021-08-24
CVE-2021-32779 Incorrectly handling of URI '#fragment' element as part of the path element CWE-551 8.6 High 2021-08-24
CVE-2021-32778 Excessive CPU utilization when closing HTTP/2 streams CWE-834 5.8 Medium 2021-08-24
CVE-2021-32777 Incorrect concatenation of multiple value request headers in ext-authz extension CWE-551 8.6 High 2021-08-24
CVE-2021-29492 Bypass of path matching rules using escaped slash characters CWE-22 8.1 High 2021-05-28
CVE-2021-21378 JWT authentication bypass with unknown issuer token CWE-287 8.2 High 2021-03-11
CVE-2020-15104 TLS Validation Vulnerability in Envoy CWE-346 4.6 Medium 2020-07-14

All 105 known CVE vulnerabilities affecting envoy with full Chinese analysis, references, and POCs where available.