envoyproxy records
113 published records for vendor envoyproxy.
Researcher profile
- Entered KEV
- 1 · 0.9%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 1
- With a fix record
- 61.9%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-416 Use After Free17
- CWE-476 NULL Pointer Dereference10
- CWE-400 Uncontrolled Resource Consumption8
- CWE-20 Improper Input Validation8
- CWE-670 Always-Incorrect Control Flow Implementation5
- CWE-770 Allocation of Resources Without Limits or Throttling3
The weakness classes this vendor ships most often: where to look.
CWEAll records
113 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
56Plan | CVE-2024-30255Proof of concept | HTTP/2: CPU exhaustion due to CONTINUATION frame floodenvoyproxy · envoy · CWE-390 | High7.5 | — | 87.8% | Apr 4, 2024 |
56Plan | CVE-2024-27919No exploit | HTTP/2: memory exhaustion due to CONTINUATION frame floodenvoyproxy · envoy · CWE-390 | High7.5 | — | 86.7% | Apr 4, 2024 |
53Plan | CVE-2021-29492No exploit | Bypass of path matching rules using escaped slash charactersenvoyproxy · envoy · CWE-22 | High8.3 | — | 66.2% | May 28, 2021 |
49Plan | CVE-2019-15226No exploit | Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headenvoyproxy · envoy · CWE-400 | High7.5 | — | 64.5% | Oct 9, 2019 |
41Plan | CVE-2019-9901No exploit | Envoy 1.9.0 and before does not normalize HTTP URL paths.envoyproxy · envoy · CWE-706 | Critical10.0 | — | 5.0% | Apr 25, 2019 |
40Plan | CVE-2019-18801No exploit | An issue was discovered in Envoy 1.12.0.envoyproxy · envoy · CWE-787 | Critical9.8 | — | 2.5% | Dec 13, 2019 |
40Plan | CVE-2019-18802No exploit | An issue was discovered in Envoy 1.12.0.envoyproxy · envoy | Critical9.8 | — | 2.5% | Dec 13, 2019 |
39Monitor | CVE-2022-21654No exploit | Incorrect configuration handling allows TLS session re-use without re-validation in Envoyenvoyproxy · envoy · CWE-295 | Critical9.8 | — | 1.1% | Feb 22, 2022 |
39Monitor | CVE-2023-35941No exploit | Envoy vulnerable to OAuth2 credentials exploit with permanent validityenvoyproxy · envoy · CWE-116 | Critical9.8 | — | 0.8% | Jul 25, 2023 |
39Monitor | CVE-2023-27488No exploit | Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.envoyproxy · envoy · CWE-20 | Critical9.8 | — | 0.7% | Apr 4, 2023 |
36Monitor | CVE-2022-29226No exploit | Trivial authentication bypass in Envoyenvoyproxy · envoy · CWE-306 | Critical9.1 | — | 1.3% | Jun 9, 2022 |
36Monitor | CVE-2023-27491No exploit | Envoy forwards invalid Http2/Http3 downstream headersenvoyproxy · envoy · CWE-20 | Critical9.1 | — | 0.9% | Apr 4, 2023 |
36Monitor | CVE-2024-39305No exploit | Envoy Proxy use after free when route hash policy is configured with cookie attributesenvoyproxy · envoy · CWE-416 | Critical9.1 | — | 0.6% | Jul 1, 2024 |
36Monitor | CVE-2023-27487No exploit | Envoy client may fake the header `x-envoy-original-path`envoyproxy · envoy · CWE-20 | Critical9.1 | — | 0.6% | Apr 4, 2023 |
36Monitor | CVE-2023-27493No exploit | Envoy doesn't escape HTTP header valuesenvoyproxy · envoy · CWE-20 | Critical9.1 | — | 0.5% | Apr 4, 2023 |
35Monitor | CVE-2020-35470No exploit | Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the penvoyproxy · envoy | High8.8 | — | 1.0% | Dec 14, 2020 |
35Monitor | CVE-2026-22771No exploit | Envoy Extension Policy lua scripts injection causes arbitrary command executionenvoyproxy · gateway · CWE-94 | High8.8 | — | 0.6% | Jan 12, 2026 |
35Monitor | CVE-2025-55162No exploit | Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flagenvoyproxy · envoy · CWE-613 | High8.8 | — | 0.3% | Sep 3, 2025 |
34Monitor | CVE-2019-9900No exploit | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0).envoyproxy · envoy · CWE-74 | High8.3 | — | 3.7% | Apr 25, 2019 |
34Monitor | CVE-2021-32777No exploit | Incorrect concatenation of multiple value request headers in ext-authz extensionenvoyproxy · envoy · CWE-551 | High8.3 | — | 3.3% | Aug 24, 2021 |
34Monitor | CVE-2021-39162No exploit | Incorrect handling of H2 GOAWAY + SETTINGS framespomerium · pomerium · CWE-754 | High8.6 | — | 1.6% | Sep 9, 2021 |
34Monitor | CVE-2021-39206No exploit | Incorrect Authorization with specially crafted requestspomerium · pomerium · CWE-863 | High8.6 | — | 1.5% | Sep 9, 2021 |
33Monitor | CVE-2021-21378No exploit | JWT authentication bypass with unknown issuer tokenenvoyproxy · envoy · CWE-287 | High8.2 | — | 1.7% | Mar 10, 2021 |
33Monitor | CVE-2020-25017No exploit | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers.envoyproxy · envoy | High8.3 | — | 1.3% | Oct 1, 2020 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2024-3025556Plan
HTTP/2: CPU exhaustion due to CONTINUATION frame flood
HighCVSS 7.5Proof of conceptEPSS 88%envoyproxy · envoyApr 4, 2024
- CVE-2024-2791956Plan
HTTP/2: memory exhaustion due to CONTINUATION frame flood
HighCVSS 7.5No exploitEPSS 87%envoyproxy · envoyApr 4, 2024
- CVE-2021-2949253Plan
Bypass of path matching rules using escaped slash characters
HighCVSS 8.3No exploitEPSS 66%envoyproxy · envoyMay 28, 2021
- CVE-2019-1522649Plan
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the head
HighCVSS 7.5No exploitEPSS 65%envoyproxy · envoyOct 9, 2019
- CVE-2019-990141Plan
Envoy 1.9.0 and before does not normalize HTTP URL paths.
CriticalCVSS 10.0No exploitEPSS 5%envoyproxy · envoyApr 25, 2019
- CVE-2019-1880140Plan
An issue was discovered in Envoy 1.12.0.
CriticalCVSS 9.8No exploitEPSS 3%envoyproxy · envoyDec 13, 2019
- CVE-2019-1880240Plan
An issue was discovered in Envoy 1.12.0.
CriticalCVSS 9.8No exploitEPSS 2%envoyproxy · envoyDec 13, 2019
- CVE-2022-2165439Monitor
Incorrect configuration handling allows TLS session re-use without re-validation in Envoy
CriticalCVSS 9.8No exploitEPSS 1%envoyproxy · envoyFeb 22, 2022
- CVE-2023-3594139Monitor
Envoy vulnerable to OAuth2 credentials exploit with permanent validity
CriticalCVSS 9.8No exploitEPSS 1%envoyproxy · envoyJul 25, 2023
- CVE-2023-2748839Monitor
Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
CriticalCVSS 9.8No exploitEPSS 1%envoyproxy · envoyApr 4, 2023
- CVE-2022-2922636Monitor
Trivial authentication bypass in Envoy
CriticalCVSS 9.1No exploitEPSS 1%envoyproxy · envoyJun 9, 2022
- CVE-2023-2749136Monitor
Envoy forwards invalid Http2/Http3 downstream headers
CriticalCVSS 9.1No exploitEPSS 1%envoyproxy · envoyApr 4, 2023
- CVE-2024-3930536Monitor
Envoy Proxy use after free when route hash policy is configured with cookie attributes
CriticalCVSS 9.1No exploitEPSS 1%envoyproxy · envoyJul 1, 2024
- CVE-2023-2748736Monitor
Envoy client may fake the header `x-envoy-original-path`
CriticalCVSS 9.1No exploitEPSS 1%envoyproxy · envoyApr 4, 2023
- CVE-2023-2749336Monitor
Envoy doesn't escape HTTP header values
CriticalCVSS 9.1No exploitEPSS 1%envoyproxy · envoyApr 4, 2023
- CVE-2020-3547035Monitor
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the p
HighCVSS 8.8No exploitEPSS 1%envoyproxy · envoyDec 14, 2020
- CVE-2026-2277135Monitor
Envoy Extension Policy lua scripts injection causes arbitrary command execution
HighCVSS 8.8No exploitEPSS 1%envoyproxy · gatewayJan 12, 2026
- CVE-2025-5516235Monitor
Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag
HighCVSS 8.8No exploitEPSS 0%envoyproxy · envoySep 3, 2025
- CVE-2019-990034Monitor
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0).
HighCVSS 8.3No exploitEPSS 4%envoyproxy · envoyApr 25, 2019
- CVE-2021-3277734Monitor
Incorrect concatenation of multiple value request headers in ext-authz extension
HighCVSS 8.3No exploitEPSS 3%envoyproxy · envoyAug 24, 2021
- CVE-2021-3916234Monitor
Incorrect handling of H2 GOAWAY + SETTINGS frames
HighCVSS 8.6No exploitEPSS 2%pomerium · pomeriumSep 9, 2021
- CVE-2021-3920634Monitor
Incorrect Authorization with specially crafted requests
HighCVSS 8.6No exploitEPSS 1%pomerium · pomeriumSep 9, 2021
- CVE-2021-2137833Monitor
JWT authentication bypass with unknown issuer token
HighCVSS 8.2No exploitEPSS 2%envoyproxy · envoyMar 10, 2021
- CVE-2020-2501733Monitor
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers.
HighCVSS 8.3No exploitEPSS 1%envoyproxy · envoyOct 1, 2020