Skip to content
Noroxi

envoyproxy records

113 published records for vendor envoyproxy.

Researcher profile

Entered KEV
1 · 0.9%
Weaponized
1 · 0.9%
Pre-auth RCE
1
With a fix record
61.9%
Median publish → KEV
0 days

All records

113 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • HTTP/2: CPU exhaustion due to CONTINUATION frame flood

    HighCVSS 7.5Proof of conceptEPSS 88%

    envoyproxy · envoyApr 4, 2024

  • HTTP/2: memory exhaustion due to CONTINUATION frame flood

    HighCVSS 7.5No exploitEPSS 87%

    envoyproxy · envoyApr 4, 2024

  • Bypass of path matching rules using escaped slash characters

    HighCVSS 8.3No exploitEPSS 66%

    envoyproxy · envoyMay 28, 2021

  • Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the head

    HighCVSS 7.5No exploitEPSS 65%

    envoyproxy · envoyOct 9, 2019

  • Envoy 1.9.0 and before does not normalize HTTP URL paths.

    CriticalCVSS 10.0No exploitEPSS 5%

    envoyproxy · envoyApr 25, 2019

  • An issue was discovered in Envoy 1.12.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    envoyproxy · envoyDec 13, 2019

  • An issue was discovered in Envoy 1.12.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    envoyproxy · envoyDec 13, 2019

  • Incorrect configuration handling allows TLS session re-use without re-validation in Envoy

    CriticalCVSS 9.8No exploitEPSS 1%

    envoyproxy · envoyFeb 22, 2022

  • Envoy vulnerable to OAuth2 credentials exploit with permanent validity

    CriticalCVSS 9.8No exploitEPSS 1%

    envoyproxy · envoyJul 25, 2023

  • Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.

    CriticalCVSS 9.8No exploitEPSS 1%

    envoyproxy · envoyApr 4, 2023

  • Trivial authentication bypass in Envoy

    CriticalCVSS 9.1No exploitEPSS 1%

    envoyproxy · envoyJun 9, 2022

  • Envoy forwards invalid Http2/Http3 downstream headers

    CriticalCVSS 9.1No exploitEPSS 1%

    envoyproxy · envoyApr 4, 2023

  • Envoy Proxy use after free when route hash policy is configured with cookie attributes

    CriticalCVSS 9.1No exploitEPSS 1%

    envoyproxy · envoyJul 1, 2024

  • Envoy client may fake the header `x-envoy-original-path`

    CriticalCVSS 9.1No exploitEPSS 1%

    envoyproxy · envoyApr 4, 2023

  • Envoy doesn't escape HTTP header values

    CriticalCVSS 9.1No exploitEPSS 1%

    envoyproxy · envoyApr 4, 2023

  • Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the p

    HighCVSS 8.8No exploitEPSS 1%

    envoyproxy · envoyDec 14, 2020

  • Envoy Extension Policy lua scripts injection causes arbitrary command execution

    HighCVSS 8.8No exploitEPSS 1%

    envoyproxy · gatewayJan 12, 2026

  • Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag

    HighCVSS 8.8No exploitEPSS 0%

    envoyproxy · envoySep 3, 2025

  • CVE-2019-9900
    34Monitor

    When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0).

    HighCVSS 8.3No exploitEPSS 4%

    envoyproxy · envoyApr 25, 2019

  • Incorrect concatenation of multiple value request headers in ext-authz extension

    HighCVSS 8.3No exploitEPSS 3%

    envoyproxy · envoyAug 24, 2021

  • Incorrect handling of H2 GOAWAY + SETTINGS frames

    HighCVSS 8.6No exploitEPSS 2%

    pomerium · pomeriumSep 9, 2021

  • Incorrect Authorization with specially crafted requests

    HighCVSS 8.6No exploitEPSS 1%

    pomerium · pomeriumSep 9, 2021

  • JWT authentication bypass with unknown issuer token

    HighCVSS 8.2No exploitEPSS 2%

    envoyproxy · envoyMar 10, 2021

  • Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers.

    HighCVSS 8.3No exploitEPSS 1%

    envoyproxy · envoyOct 1, 2020