Exposição de Envoy

Reverse proxies
67
score de exposição
103.759
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 78 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Envoy apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica ausência de exploração confirmada em campo até o momento. Ainda assim, o escore EPSS de 0,8781 associado a CVE-2024-30255 sinaliza probabilidade elevada de exploração futura, merecendo atenção prioritária nas equipes de resposta. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade com potencial de impacto severo em tempo de execução, especialmente em proxies de alto throughput como o Envoy. A presença de apenas uma CVE crítica e duas ocorrências nos últimos 90 dias sugere ritmo moderado de descobertas recentes, mas o perfil de risco não deve ser subestimado dado o valor EPSS observado.

CVEs

92 resultados
CVE-2024-53269MEDIUMHappy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoyEPSS 0.7%CVE-2024-32976HIGHEnvoy can enter an endless loop while decompressing Brotli data with extra inputEPSS 0.7%CVE-2024-23322HIGHEnvoy crashes when idle and request per try timeout occur within the backoff intervalEPSS 0.7%CVE-2024-34363HIGHEnvoy can crash due to uncaught nlohmann JSON exceptionEPSS 0.7%CVE-2022-21656HIGHX.509 subjectAltName matching bypass in EnvoyEPSS 0.7%CVE-2026-47220HIGHEnvoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log formatEPSS 0.7%CVE-2023-35943MEDIUMEnvoy vulnerable to CORS filter segfault when origin header is removed EPSS 0.7%CVE-2024-39305MEDIUMEnvoy Proxy use after free when route hash policy is configured with cookie attributesEPSS 0.6%CVE-2024-45810MEDIUMEnvoy crashes for LocalReply in http async clientEPSS 0.6%CVE-2023-27487HIGHEnvoy client may fake the header `x-envoy-original-path`EPSS 0.6%CVE-2024-53271HIGHHTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoyEPSS 0.6%CVE-2026-48706MEDIUMEnvoy Heap Buffer Overflow in TcpStatsdSinkEPSS 0.6%CVE-2024-23324HIGHEnvoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadataEPSS 0.6%CVE-2024-34362MEDIUMEnvoy affected by a crash (use-after-free) in EnvoyQuicServerStreamEPSS 0.6%CVE-2026-48090MEDIUMEnvoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)EPSS 0.6%CVE-2026-48042HIGHEnvoy: Stack overflow in destructor of highly nested JSONEPSS 0.6%CVE-2025-64527MEDIUMEnvoy crashes when JWT authentication is configured with the remote JWKS fetchingEPSS 0.5%CVE-2022-21657MEDIUMX.509 Extended Key Usage and Trust Purposes bypass in EnvoyEPSS 0.5%CVE-2023-27493HIGHEnvoy doesn't escape HTTP header valuesEPSS 0.5%CVE-2024-23323MEDIUMExcessive CPU usage when URI template matcher is configured using regex in EnvoyEPSS 0.5%