Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2023-27491 Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines… Envoy 1.22.9 / 1.23.6+ Fix from $2,3002023-04-04 MEDIUM 6.5 CVE-2023-27492 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $1,6002023-04-04 CRITICAL 9.8 CVE-2023-27488 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $2,3002023-04-04 CRITICAL 9.1 CVE-2023-27487 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $2,3002023-04-04 CRITICAL 9.1 CVE-2022-29226 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validati… Envoy 1.22.1+ Fix from $2,3002022-06-09 HIGH 7.5 CVE-2022-29225 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer be… Envoy 1.22.1+ Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-29227 Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an … Envoy 1.22.1+ Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-29228 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain a… Envoy 1.22.1+ Fix from $1,9502022-06-09 MEDIUM 5.9 CVE-2022-29224 Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. E… Envoy 1.22.1+ Fix from $1,6002022-06-09 CRITICAL 9.8 CVE-2022-21654 Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings … Envoy 1.18.6 / 1.19.3+ Fix from $2,3002022-02-22 HIGH 7.5 CVE-2022-21655 Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect… Envoy 1.18.6 / 1.19.3+ Fix from $1,9502022-02-22 MEDIUM 6.5 CVE-2022-21657 Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certi… Envoy 1.18.6 / 1.19.3+ Fix from $1,6002022-02-22 MEDIUM 6.5 CVE-2022-23606 Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS)… Envoy 1.20.2+ Fix from $1,6002022-02-22 MEDIUM 5.9 CVE-2022-21656 Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the… Envoy 1.20.2+ Fix from $1,6002022-02-22 HIGH 7.5 CVE-2021-43824 Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a C… Envoy 1.18.6 / 1.19.3+ Fix from $1,9502022-02-22 HIGH 7.5 CVE-2021-43825 Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated response must stop further proces… Envoy 1.18.6 / 1.19.3+ Fix from $1,9502022-02-22 HIGH 7.5 CVE-2021-43826 Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured … Envoy 1.18.6 / 1.19.3+ Fix from $1,9502022-02-22 HIGH 8.6 CVE-2021-39206 Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-202… Envoy 0.14.8 / 1.16.5+ Fix from $1,9502021-09-09 HIGH 8.6 CVE-2021-39162 Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS fra… Envoy 1.18.4+ Fix from $1,9502021-09-09 HIGH 7.5 CVE-2021-39204 Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with exces… Envoy 0.14.8 / 1.17.4+ Fix from $1,9502021-09-09 HIGH 7.5 CVE-2021-32781 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sen… Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 8.3 CVE-2021-32779 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrect… Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 7.5 CVE-2021-32778 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy’s procedu… Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 7.5 CVE-2021-32780 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitio… Envoy 1.18.4+ Fix from $1,9502021-08-24 HIGH 8.3 CVE-2021-32777 Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz … Envoy 1.16.5 / 1.17.4+ Fix from $1,9502021-08-24 HIGH 8.3 CVE-2021-29492EPSS 68% Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2… Envoy 1.15.5 / 1.16.4+ Fix from $1,9502021-05-28 HIGH 7.5 CVE-2021-28682 An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to u… Envoy No fix yet Fix from $1,9502021-05-20 HIGH 7.5 CVE-2021-28683 An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert … Envoy Mitigation only Fix from $1,9502021-05-20 HIGH 7.5 CVE-2021-29258 An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable… Envoy Patch available Fix from $1,9502021-05-20 HIGH 8.2 CVE-2021-21378 Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT… Envoy Patch available Fix from $1,9502021-03-11