envoyproxy kayıtları
envoyproxy üreticisine ait 113 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,9
- Silahlaştırılmış
- 1 · %0,9
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %61,9
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-416 Use After Free17
- CWE-476 NULL Pointer Dereference10
- CWE-400 Uncontrolled Resource Consumption8
- CWE-20 Improper Input Validation8
- CWE-670 Always-Incorrect Control Flow Implementation5
- CWE-770 Allocation of Resources Without Limits or Throttling3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
113 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
56Planlayın | CVE-2024-30255Kavram kanıtı | HTTP/2: CPU exhaustion due to CONTINUATION frame floodenvoyproxy · envoy · CWE-390 | Yüksek7,5 | — | %87,8 | 4 Nis 2024 |
56Planlayın | CVE-2024-27919İstismar yok | HTTP/2: memory exhaustion due to CONTINUATION frame floodenvoyproxy · envoy · CWE-390 | Yüksek7,5 | — | %86,7 | 4 Nis 2024 |
53Planlayın | CVE-2021-29492İstismar yok | Bypass of path matching rules using escaped slash charactersenvoyproxy · envoy · CWE-22 | Yüksek8,3 | — | %66,2 | 28 May 2021 |
49Planlayın | CVE-2019-15226İstismar yok | Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headenvoyproxy · envoy · CWE-400 | Yüksek7,5 | — | %64,5 | 9 Eki 2019 |
41Planlayın | CVE-2019-9901İstismar yok | Envoy 1.9.0 and before does not normalize HTTP URL paths.envoyproxy · envoy · CWE-706 | Kritik10,0 | — | %5,0 | 25 Nis 2019 |
40Planlayın | CVE-2019-18801İstismar yok | An issue was discovered in Envoy 1.12.0.envoyproxy · envoy · CWE-787 | Kritik9,8 | — | %2,5 | 13 Ara 2019 |
40Planlayın | CVE-2019-18802İstismar yok | An issue was discovered in Envoy 1.12.0.envoyproxy · envoy | Kritik9,8 | — | %2,5 | 13 Ara 2019 |
39İzleyin | CVE-2022-21654İstismar yok | Incorrect configuration handling allows TLS session re-use without re-validation in Envoyenvoyproxy · envoy · CWE-295 | Kritik9,8 | — | %1,1 | 22 Şub 2022 |
39İzleyin | CVE-2023-35941İstismar yok | Envoy vulnerable to OAuth2 credentials exploit with permanent validityenvoyproxy · envoy · CWE-116 | Kritik9,8 | — | %0,8 | 25 Tem 2023 |
39İzleyin | CVE-2023-27488İstismar yok | Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.envoyproxy · envoy · CWE-20 | Kritik9,8 | — | %0,7 | 4 Nis 2023 |
36İzleyin | CVE-2022-29226İstismar yok | Trivial authentication bypass in Envoyenvoyproxy · envoy · CWE-306 | Kritik9,1 | — | %1,3 | 9 Haz 2022 |
36İzleyin | CVE-2023-27491İstismar yok | Envoy forwards invalid Http2/Http3 downstream headersenvoyproxy · envoy · CWE-20 | Kritik9,1 | — | %0,9 | 4 Nis 2023 |
36İzleyin | CVE-2024-39305İstismar yok | Envoy Proxy use after free when route hash policy is configured with cookie attributesenvoyproxy · envoy · CWE-416 | Kritik9,1 | — | %0,6 | 1 Tem 2024 |
36İzleyin | CVE-2023-27487İstismar yok | Envoy client may fake the header `x-envoy-original-path`envoyproxy · envoy · CWE-20 | Kritik9,1 | — | %0,6 | 4 Nis 2023 |
36İzleyin | CVE-2023-27493İstismar yok | Envoy doesn't escape HTTP header valuesenvoyproxy · envoy · CWE-20 | Kritik9,1 | — | %0,5 | 4 Nis 2023 |
35İzleyin | CVE-2020-35470İstismar yok | Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the penvoyproxy · envoy | Yüksek8,8 | — | %1,0 | 14 Ara 2020 |
35İzleyin | CVE-2026-22771İstismar yok | Envoy Extension Policy lua scripts injection causes arbitrary command executionenvoyproxy · gateway · CWE-94 | Yüksek8,8 | — | %0,6 | 12 Oca 2026 |
35İzleyin | CVE-2025-55162İstismar yok | Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flagenvoyproxy · envoy · CWE-613 | Yüksek8,8 | — | %0,3 | 3 Eyl 2025 |
34İzleyin | CVE-2019-9900İstismar yok | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0).envoyproxy · envoy · CWE-74 | Yüksek8,3 | — | %3,7 | 25 Nis 2019 |
34İzleyin | CVE-2021-32777İstismar yok | Incorrect concatenation of multiple value request headers in ext-authz extensionenvoyproxy · envoy · CWE-551 | Yüksek8,3 | — | %3,3 | 24 Ağu 2021 |
34İzleyin | CVE-2021-39162İstismar yok | Incorrect handling of H2 GOAWAY + SETTINGS framespomerium · pomerium · CWE-754 | Yüksek8,6 | — | %1,6 | 9 Eyl 2021 |
34İzleyin | CVE-2021-39206İstismar yok | Incorrect Authorization with specially crafted requestspomerium · pomerium · CWE-863 | Yüksek8,6 | — | %1,5 | 9 Eyl 2021 |
33İzleyin | CVE-2021-21378İstismar yok | JWT authentication bypass with unknown issuer tokenenvoyproxy · envoy · CWE-287 | Yüksek8,2 | — | %1,7 | 10 Mar 2021 |
33İzleyin | CVE-2020-25017İstismar yok | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers.envoyproxy · envoy | Yüksek8,3 | — | %1,3 | 1 Eki 2020 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2024-3025556Planlayın
HTTP/2: CPU exhaustion due to CONTINUATION frame flood
YüksekCVSS 7,5Kavram kanıtıEPSS %88envoyproxy · envoy4 Nis 2024
- CVE-2024-2791956Planlayın
HTTP/2: memory exhaustion due to CONTINUATION frame flood
YüksekCVSS 7,5İstismar yokEPSS %87envoyproxy · envoy4 Nis 2024
- CVE-2021-2949253Planlayın
Bypass of path matching rules using escaped slash characters
YüksekCVSS 8,3İstismar yokEPSS %66envoyproxy · envoy28 May 2021
- CVE-2019-1522649Planlayın
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the head
YüksekCVSS 7,5İstismar yokEPSS %65envoyproxy · envoy9 Eki 2019
- CVE-2019-990141Planlayın
Envoy 1.9.0 and before does not normalize HTTP URL paths.
KritikCVSS 10,0İstismar yokEPSS %5envoyproxy · envoy25 Nis 2019
- CVE-2019-1880140Planlayın
An issue was discovered in Envoy 1.12.0.
KritikCVSS 9,8İstismar yokEPSS %3envoyproxy · envoy13 Ara 2019
- CVE-2019-1880240Planlayın
An issue was discovered in Envoy 1.12.0.
KritikCVSS 9,8İstismar yokEPSS %2envoyproxy · envoy13 Ara 2019
- CVE-2022-2165439İzleyin
Incorrect configuration handling allows TLS session re-use without re-validation in Envoy
KritikCVSS 9,8İstismar yokEPSS %1envoyproxy · envoy22 Şub 2022
- CVE-2023-3594139İzleyin
Envoy vulnerable to OAuth2 credentials exploit with permanent validity
KritikCVSS 9,8İstismar yokEPSS %1envoyproxy · envoy25 Tem 2023
- CVE-2023-2748839İzleyin
Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
KritikCVSS 9,8İstismar yokEPSS %1envoyproxy · envoy4 Nis 2023
- CVE-2022-2922636İzleyin
Trivial authentication bypass in Envoy
KritikCVSS 9,1İstismar yokEPSS %1envoyproxy · envoy9 Haz 2022
- CVE-2023-2749136İzleyin
Envoy forwards invalid Http2/Http3 downstream headers
KritikCVSS 9,1İstismar yokEPSS %1envoyproxy · envoy4 Nis 2023
- CVE-2024-3930536İzleyin
Envoy Proxy use after free when route hash policy is configured with cookie attributes
KritikCVSS 9,1İstismar yokEPSS %1envoyproxy · envoy1 Tem 2024
- CVE-2023-2748736İzleyin
Envoy client may fake the header `x-envoy-original-path`
KritikCVSS 9,1İstismar yokEPSS %1envoyproxy · envoy4 Nis 2023
- CVE-2023-2749336İzleyin
Envoy doesn't escape HTTP header values
KritikCVSS 9,1İstismar yokEPSS %1envoyproxy · envoy4 Nis 2023
- CVE-2020-3547035İzleyin
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the p
YüksekCVSS 8,8İstismar yokEPSS %1envoyproxy · envoy14 Ara 2020
- CVE-2026-2277135İzleyin
Envoy Extension Policy lua scripts injection causes arbitrary command execution
YüksekCVSS 8,8İstismar yokEPSS %1envoyproxy · gateway12 Oca 2026
- CVE-2025-5516235İzleyin
Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag
YüksekCVSS 8,8İstismar yokEPSS %0envoyproxy · envoy3 Eyl 2025
- CVE-2019-990034İzleyin
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0).
YüksekCVSS 8,3İstismar yokEPSS %4envoyproxy · envoy25 Nis 2019
- CVE-2021-3277734İzleyin
Incorrect concatenation of multiple value request headers in ext-authz extension
YüksekCVSS 8,3İstismar yokEPSS %3envoyproxy · envoy24 Ağu 2021
- CVE-2021-3916234İzleyin
Incorrect handling of H2 GOAWAY + SETTINGS frames
YüksekCVSS 8,6İstismar yokEPSS %2pomerium · pomerium9 Eyl 2021
- CVE-2021-3920634İzleyin
Incorrect Authorization with specially crafted requests
YüksekCVSS 8,6İstismar yokEPSS %1pomerium · pomerium9 Eyl 2021
- CVE-2021-2137833İzleyin
JWT authentication bypass with unknown issuer token
YüksekCVSS 8,2İstismar yokEPSS %2envoyproxy · envoy10 Mar 2021
- CVE-2020-2501733İzleyin
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers.
YüksekCVSS 8,3İstismar yokEPSS %1envoyproxy · envoy1 Eki 2020