Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

envoyproxy — Vulnerabilities & Security Advisories 88

Browse all 88 CVE security advisories affecting envoyproxy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Envoyproxy serves as a high-performance, open-source edge and service proxy, primarily deployed in cloud-native environments to manage ingress and egress traffic. Despite its architectural robustness, the project has accumulated 73 recorded Common Vulnerabilities and Exposures, reflecting the complexity of its extensive feature set. Historically, these security flaws predominantly involve memory corruption issues, such as buffer overflows and use-after-free errors, which can lead to remote code execution or denial-of-service conditions. While cross-site scripting and privilege escalation are less frequent, configuration errors and parsing vulnerabilities remain significant risks. Notable incidents often stem from improper input validation in HTTP/2 or gRPC handling, allowing attackers to crash proxies or bypass access controls. Continuous patching and strict configuration management are essential for maintaining the integrity of deployments relying on this critical infrastructure component.

Found 85 results / 88 Clear Filters
Top products by envoyproxy: envoy gateway
CVE ID Title CVSS Severity Published
CVE-2023-27492 Envoy may crash when a large request body is processed in Lua filter — envoy CWE-770 4.8 Medium 2023-04-04
CVE-2023-27491 Envoy forwards invalid Http2/Http3 downstream headers — envoy CWE-20 5.4 Medium 2023-04-04
CVE-2023-27488 Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received. — envoy CWE-20 5.4 Medium 2023-04-04
CVE-2023-27487 Envoy client may fake the header `x-envoy-original-path` — envoy CWE-20 8.2 High 2023-04-04
CVE-2022-29227 Use after free in Envoy — envoy CWE-416 7.5 High 2022-06-09
CVE-2022-29226 Trivial authentication bypass in Envoy — envoy CWE-306 10.0 Critical 2022-06-09
CVE-2022-29228 Reachable assertion in Envoy — envoy CWE-617 7.5 High 2022-06-09
CVE-2022-29225 Zip bomb vulnerability in Envoy — envoy CWE-400 7.5 High 2022-06-09
CVE-2022-29224 Segmentation fault leading to crash in Envoy — envoy CWE-476 5.9 Medium 2022-06-09
CVE-2021-43826 Crash when tunneling TCP over HTTP in Envoy — envoy CWE-416 7.5 High 2022-02-22
CVE-2021-43825 Use-after-free in Envoy — envoy CWE-416 6.1 Medium 2022-02-22
CVE-2022-21655 Incorrect handling of internal redirects results in crash in Envoy — envoy CWE-670 7.5 High 2022-02-22
CVE-2022-21654 Incorrect configuration handling allows TLS session re-use without re-validation in Envoy — envoy CWE-295 7.4 High 2022-02-22
CVE-2022-21657 X.509 Extended Key Usage and Trust Purposes bypass in Envoy — envoy CWE-295 6.8 Medium 2022-02-22
CVE-2022-21656 X.509 subjectAltName matching bypass in Envoy — envoy CWE-295 7.4 High 2022-02-22
CVE-2022-23606 Crash when a cluster is deleted in Envoy — envoy CWE-674 4.4 Medium 2022-02-22
CVE-2021-43824 Null pointer dereference in envoy — envoy CWE-476 7.5 High 2022-02-22
CVE-2021-32780 Incorrect handling of H/2 GOAWAY followed by SETTINGS frames — envoy CWE-754 8.6 High 2021-08-24
CVE-2021-32781 Continued processing of requests after locally generated response — envoy CWE-416 8.6 High 2021-08-24
CVE-2021-32779 Incorrectly handling of URI '#fragment' element as part of the path element — envoy CWE-551 8.6 High 2021-08-24
CVE-2021-32778 Excessive CPU utilization when closing HTTP/2 streams — envoy CWE-834 5.8 Medium 2021-08-24
CVE-2021-32777 Incorrect concatenation of multiple value request headers in ext-authz extension — envoy CWE-551 8.6 High 2021-08-24
CVE-2021-29492 Bypass of path matching rules using escaped slash characters — envoy CWE-22 8.1 High 2021-05-28
CVE-2021-21378 JWT authentication bypass with unknown issuer token — envoy CWE-287 8.2 High 2021-03-11
CVE-2020-15104 TLS Validation Vulnerability in Envoy — envoy CWE-346 4.6 Medium 2020-07-14

This page lists every published CVE security advisory associated with envoyproxy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.