Exposure of Envoy
Reverse proxies65
exposure score
103,759
sites use
0
exploited
1
critical
CVEs
105 resultsCVE-2026-47221MEDIUMEnvoy: Null pointer deref in internal redirectsEPSS 0.4%CVE-2026-47207MEDIUMEnvoy crashes if multiple unexpected ext_proc responses are packed into one gRPC messageEPSS 0.4%CVE-2026-26309MEDIUMEnvoy has an off-by-one write in JsonEscaper::escapeString()EPSS 0.4%CVE-2025-30157MEDIUMEnvoy crashes when HTTP ext_proc processes local repliesEPSS 0.4%CVE-2025-62504MEDIUMEnvoy Lua filter use-after-free when oversized rewritten response body causes crashEPSS 0.4%CVE-2026-48497MEDIUMEnvoy: Abnormal process termination in DNS UDP filterEPSS 0.4%CVE-2024-45809MEDIUMJwt filter crash in the clear route cache with remote JWKs in envoyEPSS 0.4%CVE-2026-6994MEDIUMEnvoy Query Parameter header_mutation.cc params.add injectionEPSS 0.4%CVE-2026-26330MEDIUMEnvoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directlyEPSS 0.4%CVE-2026-47205MEDIUMEnvoy: ext_authz Use-After-Free during Stream Teardown with Per-Route OverridesEPSS 0.4%CVE-2024-45806MEDIUMPotential manipulate `x-envoy` headers from external sources in envoyEPSS 0.4%CVE-2026-73511MEDIUMEnvoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat)EPSS 0.4%CVE-2024-23326MEDIUMEnvoy incorrectly accepts HTTP 200 response for entering upgrade modeEPSS 0.4%CVE-2026-26308HIGHEnvoy has an RBAC Header Validation Bypass via Multi-Value Header ConcatenationEPSS 0.4%CVE-2024-45808MEDIUMMalicious log injection via access logs in envoyEPSS 0.4%CVE-2025-55162MEDIUMEnvoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flagEPSS 0.3%CVE-2025-64763LOWEnvoy forwards early CONNECT data in TCP proxy modeEPSS 0.3%CVE-2026-48743HIGHEnvoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-LengthEPSS 0.3%CVE-2024-21881HIGHUpload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.xEPSS 0.3%CVE-2025-46821MEDIUMEnvoy vulnerable to bypass of RBAC uri_template permissionEPSS 0.3%