vendor

envoyproxy

17 thingsrelated by NVD
Severity

Its products

envoy 17

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled
CVE-2026-73553
Severity high
envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values
CVE-2026-73552
Severity high
envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters
CVE-2026-73551
Severity medium
envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits
CVE-2026-73550
Severity high
envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters
CVE-2026-73549
Severity medium
envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests
CVE-2026-73548
Severity high
envoy: envoy: stored XSS through dynamically generated stat names in admin interface
CVE-2026-73546
Severity high
envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free
CVE-2026-73513
Severity high
envoy: envoy: HTTP/3 use-after-free when processing late datagrams
CVE-2026-73512
Severity high
envoy: envoy: path matching bypass via per-segment parameters not stripped by router
CVE-2026-73511
Severity medium
envoy: envoy: ext_authz use-after-free after rejecting an HTTP request
CVE-2026-50572
Severity medium
envoy: envoy: HTTP/3 null transport socket options dereference during connection-pool selection
CVE-2026-48521
Severity medium
envoy: Envoy: mTLS certificate validation bypass via embedded null byte in SAN
CVE-2025-66220
Severity high
envoy: Envoy: Remote JWT authentication token fetch crash
CVE-2025-64527
Severity medium
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted…
CVE-2020-8664
Severity medium
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CVE-2020-8661
Severity high
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1…
CVE-2020-8659
Severity high