Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Envoy CRITICAL 9.1
CVE-2023-27491

Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines…

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy MEDIUM 6.5
CVE-2023-27492

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $1,600 2023-04-04
Envoy CRITICAL 9.8
CVE-2023-27488

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy CRITICAL 9.1
CVE-2023-27487

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $2,300 2023-04-04
Envoy CRITICAL 9.1
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validati…

Fix: 1.22.1+
Fix from $2,300 2022-06-09
Envoy HIGH 7.5
CVE-2022-29225

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer be…

Fix: 1.22.1+
Fix from $1,950 2022-06-09
Envoy HIGH 7.5
CVE-2022-29227

Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an …

Fix: 1.22.1+
Fix from $1,950 2022-06-09
Envoy HIGH 7.5
CVE-2022-29228

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain a…

Fix: 1.22.1+
Fix from $1,950 2022-06-09
Envoy MEDIUM 5.9
CVE-2022-29224

Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. E…

Fix: 1.22.1+
Fix from $1,600 2022-06-09
Envoy CRITICAL 9.8
CVE-2022-21654

Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings …

Fix: 1.18.6 / 1.19.3+
Fix from $2,300 2022-02-22
Envoy HIGH 7.5
CVE-2022-21655

Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect…

Fix: 1.18.6 / 1.19.3+
Fix from $1,950 2022-02-22
Envoy MEDIUM 6.5
CVE-2022-21657

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certi…

Fix: 1.18.6 / 1.19.3+
Fix from $1,600 2022-02-22
Envoy MEDIUM 6.5
CVE-2022-23606

Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS)…

Fix: 1.20.2+
Fix from $1,600 2022-02-22
Envoy MEDIUM 5.9
CVE-2022-21656

Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the…

Fix: 1.20.2+
Fix from $1,600 2022-02-22
Envoy HIGH 7.5
CVE-2021-43824

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a C…

Fix: 1.18.6 / 1.19.3+
Fix from $1,950 2022-02-22
Envoy HIGH 7.5
CVE-2021-43825

Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further proces…

Fix: 1.18.6 / 1.19.3+
Fix from $1,950 2022-02-22
Envoy HIGH 7.5
CVE-2021-43826

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured …

Fix: 1.18.6 / 1.19.3+
Fix from $1,950 2022-02-22
Envoy HIGH 8.6
CVE-2021-39206

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-202…

Fix: 0.14.8 / 1.16.5+
Fix from $1,950 2021-09-09
Envoy HIGH 8.6
CVE-2021-39162

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS fra…

Fix: 1.18.4+
Fix from $1,950 2021-09-09
Envoy HIGH 7.5
CVE-2021-39204

Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with exces…

Fix: 0.14.8 / 1.17.4+
Fix from $1,950 2021-09-09
Envoy HIGH 7.5
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sen…

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Envoy HIGH 8.3
CVE-2021-32779

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrect…

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Envoy HIGH 7.5
CVE-2021-32778

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedu…

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Envoy HIGH 7.5
CVE-2021-32780

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitio…

Fix: 1.18.4+
Fix from $1,950 2021-08-24
Envoy HIGH 8.3
CVE-2021-32777

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz …

Fix: 1.16.5 / 1.17.4+
Fix from $1,950 2021-08-24
Envoy HIGH 8.3
CVE-2021-29492EPSS 68%

Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2…

Fix: 1.15.5 / 1.16.4+
Fix from $1,950 2021-05-28
Envoy HIGH 7.5
CVE-2021-28682

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to u…

No fix yet
Fix from $1,950 2021-05-20
Envoy HIGH 7.5
CVE-2021-28683

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert …

Mitigation only
Fix from $1,950 2021-05-20
Envoy HIGH 7.5
CVE-2021-29258

An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable…

Patch available
Fix from $1,950 2021-05-20
Envoy HIGH 8.2
CVE-2021-21378

Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT…

Patch available
Fix from $1,950 2021-03-11