Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Envoy HIGH 7.5
CVE-2024-53270

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request ex…

Fix: 1.29.12 / 1.30.9+
Fix from $1,950 2024-12-18
Envoy HIGH 7.1
CVE-2024-53271

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx respons…

Fix: 1.31.5+
Fix from $1,950 2024-12-18
Envoy HIGH 7.5
CVE-2024-45810

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under so…

Fix: 1.28.7 / 1.29.9+
Fix from $1,950 2024-09-20
Envoy HIGH 7.5
CVE-2024-45807

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potenti…

Fix: 1.31.2+
Fix from $1,950 2024-09-20
Envoy HIGH 7.5
CVE-2024-45809

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. I…

Fix: 1.29.9 / 1.30.6+
Fix from $1,950 2024-09-20
Envoy MEDIUM 6.5
CVE-2024-45806

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy hea…

Fix: 1.28.7 / 1.29.9+
Fix from $1,600 2024-09-20
Envoy MEDIUM 6.5
CVE-2024-45808

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to i…

Fix: 1.28.7 / 1.29.9+
Fix from $1,600 2024-09-20
Envoy CRITICAL 9.1
CVE-2024-39305

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed mem…

Patch available
Fix from $2,300 2024-07-01
Envoy HIGH 7.5
CVE-2024-32976

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Bro…

Fix: 1.27.6 / 1.28.4+
Fix from $1,950 2024-06-04
Envoy HIGH 7.5
CVE-2024-34363

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught …

Fix: 1.28.4 / 1.29.5+
Fix from $1,950 2024-06-04
Envoy MEDIUM 6.5
CVE-2024-34364

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP c…

Fix: 1.27.6 / 1.28.4+
Fix from $1,600 2024-06-04
Envoy MEDIUM 5.9
CVE-2024-34362

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` …

Fix: 1.27.6 / 1.28.4+
Fix from $1,600 2024-06-04
Envoy HIGH 8.2
CVE-2024-23326

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tr…

Fix: 1.27.6 / 1.28.4+
Fix from $1,950 2024-06-04
Envoy HIGH 7.5
CVE-2024-32974

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with followi…

Fix: 1.27.6 / 1.28.4+
Fix from $1,950 2024-06-04
Envoy HIGH 7.5
CVE-2024-32975

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer un…

Fix: 1.27.6 / 1.28.4+
Fix from $1,950 2024-06-04
Envoy HIGH 7.5
CVE-2024-32475

Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `ho…

Fix: 1.27.5 / 1.28.3+
Fix from $1,950 2024-04-18
Envoy HIGH 7.5
CVE-2024-30255EPSS 88%

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 …

Fix: 1.26.8 / 1.27.4+
Fix from $1,950 2024-04-04
Envoy HIGH 7.5
CVE-2024-27919EPSS 87%

Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood…

Patch available
Fix from $1,950 2024-04-04
Envoy HIGH 7.5
CVE-2024-23324

Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can forc…

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Envoy HIGH 7.5
CVE-2024-23325

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Env…

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Envoy HIGH 7.5
CVE-2024-23327

Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfau…

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Envoy HIGH 7.5
CVE-2024-23322

Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when …

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Envoy MEDIUM 5.3
CVE-2024-23323

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increa…

Fix: 1.26.7 / 1.27.3+
Fix from $1,600 2024-02-09
Envoy HIGH 7.5
CVE-2023-35943

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12…

Fix: 1.23.12 / 1.24.10+
Fix from $1,950 2023-07-25
Envoy MEDIUM 6.5
CVE-2023-35942

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12…

Fix: 1.23.12 / 1.24.10+
Fix from $1,600 2023-07-25
Envoy MEDIUM 5.3
CVE-2023-35944

Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some inter…

Fix: 1.23.12 / 1.24.10+
Fix from $1,600 2023-07-25
Envoy CRITICAL 9.8
CVE-2023-35941

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12…

Fix: 1.23.12 / 1.24.10+
Fix from $2,300 2023-07-25
Envoy HIGH 7.5
CVE-2023-35945

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiv…

Fix: 1.23.11 / 1.24.9+
Fix from $1,950 2023-07-13
Envoy CRITICAL 9.1
CVE-2023-27493

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy HIGH 7.5
CVE-2023-27496

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $1,950 2023-04-04