Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

envoyproxy — Vulnerabilities & Security Advisories 88

Browse all 88 CVE security advisories affecting envoyproxy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Envoyproxy serves as a high-performance, open-source edge and service proxy, primarily deployed in cloud-native environments to manage ingress and egress traffic. Despite its architectural robustness, the project has accumulated 73 recorded Common Vulnerabilities and Exposures, reflecting the complexity of its extensive feature set. Historically, these security flaws predominantly involve memory corruption issues, such as buffer overflows and use-after-free errors, which can lead to remote code execution or denial-of-service conditions. While cross-site scripting and privilege escalation are less frequent, configuration errors and parsing vulnerabilities remain significant risks. Notable incidents often stem from improper input validation in HTTP/2 or gRPC handling, allowing attackers to crash proxies or bypass access controls. Continuous patching and strict configuration management are essential for maintaining the integrity of deployments relying on this critical infrastructure component.

Top products by envoyproxy: envoy gateway
CVE ID Title CVSS Severity Published
CVE-2025-25294 Envoy Gateway Log Injection Vulnerability — gateway CWE-117 5.3 Medium 2025-03-06
CVE-2025-24030 Envoy Admin Interface Exposed through prometheus metrics endpoint — gateway CWE-419 7.1 High 2025-01-23
CVE-2024-53271 HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy — envoy CWE-670 7.1 High 2024-12-18
CVE-2024-53270 HTTP/1: sending overload crashes when the request is reset beforehand in envoy — envoy CWE-670 7.5 High 2024-12-18
CVE-2024-53269 Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy — envoy CWE-670 4.5 Medium 2024-12-18
CVE-2024-45806 Potential manipulate `x-envoy` headers from external sources in envoy — envoy CWE-639 6.5 Medium 2024-09-19
CVE-2024-45807 oghttp2 crash on OnBeginHeadersForStream in envoy — envoy CWE-670 7.5 High 2024-09-19
CVE-2024-45808 Malicious log injection via access logs in envoy — envoy CWE-117 6.5 Medium 2024-09-19
CVE-2024-45809 Jwt filter crash in the clear route cache with remote JWKs in envoy — envoy CWE-119 5.3 Medium 2024-09-19
CVE-2024-45810 Envoy crashes for LocalReply in http async client — envoy CWE-119 6.5 Medium 2024-09-19
CVE-2024-39305 Envoy Proxy use after free when route hash policy is configured with cookie attributes — envoy CWE-416 6.5 Medium 2024-07-01
CVE-2024-32974 Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete() — envoy CWE-416 5.9 Medium 2024-06-04
CVE-2024-32975 Envoy crashes in QuicheDataReader::PeekVarInt62Length() — envoy CWE-191 5.9 Medium 2024-06-04
CVE-2024-32976 Envoy can enter an endless loop while decompressing Brotli data with extra input — envoy CWE-835 7.5 High 2024-06-04
CVE-2024-34362 Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream — envoy CWE-416 5.9 Medium 2024-06-04
CVE-2024-34363 Envoy can crash due to uncaught nlohmann JSON exception — envoy CWE-248 7.5 High 2024-06-04
CVE-2024-34364 Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response — envoy CWE-400 5.7 Medium 2024-06-04
CVE-2024-23326 Envoy incorrectly accepts HTTP 200 response for entering upgrade mode — envoy CWE-391 5.9 Medium 2024-06-04
CVE-2024-32475 Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes — envoy CWE-253 7.5 High 2024-04-18
CVE-2024-30255 HTTP/2: CPU exhaustion due to CONTINUATION frame flood — envoy CWE-390 5.3 Medium 2024-04-04
CVE-2024-27919 HTTP/2: memory exhaustion due to CONTINUATION frame flood — envoy CWE-390 7.5 High 2024-04-04
CVE-2024-23322 Envoy crashes when idle and request per try timeout occur within the backoff interval — envoy CWE-416 7.5 High 2024-02-09
CVE-2024-23323 Excessive CPU usage when URI template matcher is configured using regex in Envoy — envoy CWE-400 4.3 Medium 2024-02-09
CVE-2024-23324 Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadata — envoy CWE-20 8.6 High 2024-02-09
CVE-2024-23325 Envoy crashes when using an address type that isn’t supported by the OS — envoy CWE-755 7.5 High 2024-02-09
CVE-2024-23327 Crash in proxy protocol when command type of LOCAL in Envoy — envoy CWE-476 7.5 High 2024-02-09
CVE-2023-35944 Envoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemes — envoy CWE-20 8.2 High 2023-07-25
CVE-2023-35943 Envoy vulnerable to CORS filter segfault when origin header is removed — envoy CWE-416 6.3 Medium 2023-07-25
CVE-2023-35942 Envoy's gRPC access log crash caused by the listener draining — envoy CWE-416 6.5 Medium 2023-07-25
CVE-2023-35941 Envoy vulnerable to OAuth2 credentials exploit with permanent validity — envoy CWE-116 8.6 High 2023-07-25

This page lists every published CVE security advisory associated with envoyproxy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.