Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

envoyproxy — Vulnerabilities & Security Advisories 88

Browse all 88 CVE security advisories affecting envoyproxy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Envoyproxy serves as a high-performance, open-source edge and service proxy, primarily deployed in cloud-native environments to manage ingress and egress traffic. Despite its architectural robustness, the project has accumulated 73 recorded Common Vulnerabilities and Exposures, reflecting the complexity of its extensive feature set. Historically, these security flaws predominantly involve memory corruption issues, such as buffer overflows and use-after-free errors, which can lead to remote code execution or denial-of-service conditions. While cross-site scripting and privilege escalation are less frequent, configuration errors and parsing vulnerabilities remain significant risks. Notable incidents often stem from improper input validation in HTTP/2 or gRPC handling, allowing attackers to crash proxies or bypass access controls. Continuous patching and strict configuration management are essential for maintaining the integrity of deployments relying on this critical infrastructure component.

Top products by envoyproxy: envoy gateway
CVE ID Title CVSS Severity Published
CVE-2026-48090 Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk) — envoy CWE-416 5.9 Medium 2026-06-26
CVE-2026-47220 Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format — envoy CWE-476 7.5 High 2026-06-26
CVE-2026-47205 Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides — envoy CWE-416 5.9 Medium 2026-06-26
CVE-2026-47692 Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream — envoy CWE-130 4.8 Medium 2026-06-26
CVE-2026-47207 Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message — envoy CWE-416 6.5 Medium 2026-06-26
CVE-2026-48706 Envoy Heap Buffer Overflow in TcpStatsdSink — envoy CWE-120 5.9 Medium 2026-06-26
CVE-2026-47204 Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes — envoy CWE-476 6.5 Medium 2026-06-26
CVE-2026-47221 Envoy: Null pointer deref in internal redirects — envoy CWE-476 5.9 Medium 2026-06-26
CVE-2026-48743 Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length — envoy CWE-444 7.5 High 2026-06-26
CVE-2026-48497 Envoy: Abnormal process termination in DNS UDP filter — envoy CWE-480 5.9 Medium 2026-06-26
CVE-2026-48044 Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion — envoy CWE-409 7.5 High 2026-06-26
CVE-2026-48042 Envoy: Stack overflow in destructor of highly nested JSON — envoy CWE-1124 7.5 High 2026-06-26
CVE-2026-47778 Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass) — envoy CWE-158 4.4 Medium 2026-06-26
CVE-2026-47775 Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption — envoy CWE-209 6.8 Medium 2026-06-26
CVE-2026-47774 Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification — envoy CWE-405 7.5 High 2026-06-17
CVE-2026-26330 Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly — envoy CWE-416 5.3 Medium 2026-03-10
CVE-2026-26311 Envoy HTTP: filter chain execution on reset streams causing UAF crash — envoy CWE-416 5.9 Medium 2026-03-10
CVE-2026-26310 Crash for scoped ip address in Envoy during DNS — envoy CWE-20 5.9 Medium 2026-03-10
CVE-2026-26309 Envoy has an off-by-one write in JsonEscaper::escapeString() — envoy CWE-193 5.3 Medium 2026-03-10
CVE-2026-26308 Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation — envoy CWE-863 7.5 High 2026-03-10
CVE-2026-22771 Envoy Extension Policy lua scripts injection causes arbitrary command execution — gateway CWE-94 8.8 High 2026-01-12
CVE-2025-66220 Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte — envoy CWE-170 5.0 Medium 2025-12-03
CVE-2025-64763 Envoy forwards early CONNECT data in TCP proxy mode — envoy CWE-693 3.7 Low 2025-12-03
CVE-2025-64527 Envoy crashes when JWT authentication is configured with the remote JWKS fetching — envoy CWE-476 6.5 Medium 2025-12-03
CVE-2025-62504 Envoy Lua filter use-after-free when oversized rewritten response body causes crash — envoy CWE-416 6.5 Medium 2025-10-16
CVE-2025-62409 Envoy allows large requests and responses to cause TCP connection pool crash — envoy CWE-476 7.5AI High AI 2025-10-16
CVE-2025-55162 Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag — envoy CWE-613 6.3 Medium 2025-09-03
CVE-2025-54588 Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults — envoy CWE-416 7.5 High 2025-09-02
CVE-2025-46821 Envoy vulnerable to bypass of RBAC uri_template permission — envoy CWE-186 5.3 Medium 2025-05-07
CVE-2025-30157 Envoy crashes when HTTP ext_proc processes local replies — envoy CWE-460 6.5 Medium 2025-03-21

This page lists every published CVE security advisory associated with envoyproxy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.