Exposure of Envoy
Reverse proxies65
exposure score
103,759
sites use
0
exploited
1
critical
CVEs
105 resultsCVE-2026-48042HIGHEnvoy: Stack overflow in destructor of highly nested JSONEPSS 0.6%CVE-2026-73547HIGHEnvoy ext_authz: request `:path` pseudoheader dereferenced w/o null checkEPSS 0.6%CVE-2026-73550HIGHEnvoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in EnvoyEPSS 0.6%CVE-2025-64527MEDIUMEnvoy crashes when JWT authentication is configured with the remote JWKS fetchingEPSS 0.5%CVE-2026-73551MEDIUMEnvoy: Path normalization does not handle dot and dotdot segments with parametersEPSS 0.5%CVE-2022-21657MEDIUMX.509 Extended Key Usage and Trust Purposes bypass in EnvoyEPSS 0.5%CVE-2023-27493HIGHEnvoy doesn't escape HTTP header valuesEPSS 0.5%CVE-2026-73553HIGHEnvoy: RBAC Authorization Bypass via Path ParametersEPSS 0.5%CVE-2024-23323MEDIUMExcessive CPU usage when URI template matcher is configured using regex in EnvoyEPSS 0.5%CVE-2026-26311MEDIUMEnvoy HTTP: filter chain execution on reset streams causing UAF crashEPSS 0.5%CVE-2024-45807HIGHoghttp2 crash on OnBeginHeadersForStream in envoyEPSS 0.5%CVE-2026-48044HIGHEnvoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosionEPSS 0.5%CVE-2026-73513HIGHEnvoy: oghttp2 upstream trailers incorrect handlingEPSS 0.5%CVE-2025-54588HIGHEnvoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsEPSS 0.5%CVE-2026-26310MEDIUMCrash for scoped ip address in Envoy during DNSEPSS 0.5%CVE-2026-73552HIGHEnvoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header valuesEPSS 0.5%CVE-2024-34364MEDIUMEnvoy OOM vector from HTTP async client with unbounded response buffer for mirror responseEPSS 0.5%CVE-2026-73548HIGHEnvoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend poolEPSS 0.5%CVE-2025-62409MEDIUMEnvoy allows large requests and responses to cause TCP connection pool crashEPSS 0.5%CVE-2026-47204MEDIUMEnvoy: grpc_stats filter segfault on Connect protocol requests to direct_response routesEPSS 0.4%