Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-53270 Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request ex… Envoy 1.29.12 / 1.30.9+ Fix from $1,9502024-12-18 HIGH 7.1 CVE-2024-53271 Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx respons… Envoy 1.31.5+ Fix from $1,9502024-12-18 HIGH 7.5 CVE-2024-45810 Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under so… Envoy 1.28.7 / 1.29.9+ Fix from $1,9502024-09-20 HIGH 7.5 CVE-2024-45807 Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potenti… Envoy 1.31.2+ Fix from $1,9502024-09-20 HIGH 7.5 CVE-2024-45809 Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. I… Envoy 1.29.9 / 1.30.6+ Fix from $1,9502024-09-20 MEDIUM 6.5 CVE-2024-45806 Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy hea… Envoy 1.28.7 / 1.29.9+ Fix from $1,6002024-09-20 MEDIUM 6.5 CVE-2024-45808 Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to i… Envoy 1.28.7 / 1.29.9+ Fix from $1,6002024-09-20 CRITICAL 9.1 CVE-2024-39305 Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed mem… Envoy Patch available Fix from $2,3002024-07-01 HIGH 7.5 CVE-2024-32976 Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Bro… Envoy 1.27.6 / 1.28.4+ Fix from $1,9502024-06-04 HIGH 7.5 CVE-2024-34363 Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught … Envoy 1.28.4 / 1.29.5+ Fix from $1,9502024-06-04 MEDIUM 6.5 CVE-2024-34364 Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP c… Envoy 1.27.6 / 1.28.4+ Fix from $1,6002024-06-04 MEDIUM 5.9 CVE-2024-34362 Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` … Envoy 1.27.6 / 1.28.4+ Fix from $1,6002024-06-04 HIGH 8.2 CVE-2024-23326 Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tr… Envoy 1.27.6 / 1.28.4+ Fix from $1,9502024-06-04 HIGH 7.5 CVE-2024-32974 Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with followi… Envoy 1.27.6 / 1.28.4+ Fix from $1,9502024-06-04 HIGH 7.5 CVE-2024-32975 Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer un… Envoy 1.27.6 / 1.28.4+ Fix from $1,9502024-06-04 HIGH 7.5 CVE-2024-32475 Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `ho… Envoy 1.27.5 / 1.28.3+ Fix from $1,9502024-04-18 HIGH 7.5 CVE-2024-30255EPSS 88% Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 … Envoy 1.26.8 / 1.27.4+ Fix from $1,9502024-04-04 HIGH 7.5 CVE-2024-27919EPSS 87% Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood… Envoy Patch available Fix from $1,9502024-04-04 HIGH 7.5 CVE-2024-23324 Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can forc… Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2024-23325 Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Env… Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2024-23327 Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfau… Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2024-23322 Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when … Envoy 1.26.7 / 1.27.3+ Fix from $1,9502024-02-09 MEDIUM 5.3 CVE-2024-23323 Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increa… Envoy 1.26.7 / 1.27.3+ Fix from $1,6002024-02-09 HIGH 7.5 CVE-2023-35943 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12… Envoy 1.23.12 / 1.24.10+ Fix from $1,9502023-07-25 MEDIUM 6.5 CVE-2023-35942 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12… Envoy 1.23.12 / 1.24.10+ Fix from $1,6002023-07-25 MEDIUM 5.3 CVE-2023-35944 Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some inter… Envoy 1.23.12 / 1.24.10+ Fix from $1,6002023-07-25 CRITICAL 9.8 CVE-2023-35941 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12… Envoy 1.23.12 / 1.24.10+ Fix from $2,3002023-07-25 HIGH 7.5 CVE-2023-35945 Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiv… Envoy 1.23.11 / 1.24.9+ Fix from $1,9502023-07-13 CRITICAL 9.1 CVE-2023-27493 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $2,3002023-04-04 HIGH 7.5 CVE-2023-27496 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $1,9502023-04-04