Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Envoy HIGH 8.8
CVE-2020-35470

Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy prot…

Fix: 1.16.1+
Fix from $1,950 2020-12-15
Envoy HIGH 7.5
CVE-2020-35471

Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.

Fix: 1.16.1+
Fix from $1,950 2020-12-15
Envoy HIGH 8.3
CVE-2020-25017

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API d…

Fix: 1.12.7 / 1.13.4+
Fix from $1,950 2020-10-01
Envoy HIGH 7.5
CVE-2020-25018

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

Fix: 3b5acb2+
Fix from $1,950 2020-10-01
Envoy MEDIUM 5.4
CVE-2020-15104

In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Al…

Fix: 1.12.6 / 1.13.4+
Fix from $1,600 2020-07-14
Envoy HIGH 7.5
CVE-2020-8663

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.

Fix: after 1.14.2
Fix from $1,950 2020-07-01
Envoy HIGH 7.5
CVE-2020-12604

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload …

Fix: after 1.12.4
Fix from $1,950 2020-07-01
Envoy HIGH 7.5
CVE-2020-12605

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or req…

Fix: after 1.12.4
Fix from $1,950 2020-07-01
Envoy HIGH 7.5
CVE-2020-12603

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i…

Fix: after 1.12.4
Fix from $1,950 2020-07-01
Envoy MEDIUM 5.3
CVE-2020-8660

CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.…

Fix: 1.12.3 / 1.13.1+
Fix from $1,600 2020-03-04
Envoy CRITICAL 9.8
CVE-2019-18801

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers wh…

Fix: after 1.12.1
Fix from $2,300 2019-12-13
Envoy CRITICAL 9.8
CVE-2019-18802

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. …

Fix: after 1.12.1
Fix from $2,300 2019-12-13
Envoy HIGH 7.5
CVE-2019-18838

An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid re…

Fix: after 1.12.1
Fix from $1,950 2019-12-13
Envoy HIGH 7.5
CVE-2019-18836

Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker…

Fix: after 1.3.3
Fix from $1,950 2019-11-11
Envoy HIGH 7.5
CVE-2019-15226EPSS 65%

Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays…

Patch available
Fix from $1,950 2019-10-09
Envoy HIGH 7.5
CVE-2019-15225

In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote att…

Fix: after 1.11.1
Fix from $1,950 2019-08-19
Envoy CRITICAL 10.0
CVE-2019-9901

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access con…

Fix: after 1.9.0
Fix from $2,300 2019-04-25