github.com/envoyproxy/envoy
Go11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/envoyproxy/envoypage 1 of 1
- CVE-2019-9901MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.9.12019-04-25
Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized pa…
- CVE-2025-30157MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.33.12025-03-21
Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life …
- CVE-2025-54588HIGHCVSS 7.5EG 7.5✓ Fixed in 1.34.52025-09-03
vulnerable: 1.35.0
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a use-after-free (UAF) vulnerability in the DNS cache, causing abnormal proc…
- CVE-2025-64527MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.33.132025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes when JWT authentication is configured with the remote JWKS fetching, allow_missing_or_failed is enabled, multiple JWT to…
- CVE-2025-64763MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.33.132025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwar…
- CVE-2025-66220HIGHCVSS 7.1EG 7.1✓ Fixed in 1.33.132025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null by…
- CVE-2026-26308HIGHCVSS 8.2EG 8.2✓ Fixed in 1.34.132026-03-10
vulnerable: 1.37.0
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are…
- CVE-2026-26309MEDIUMCVSS 5.3EG 5.32026-03-10
vulnerable: 1.37.0
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potenti…
- CVE-2026-26310HIGHCVSS 7.5EG 7.52026-03-10
vulnerable: 1.37.0
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scoped IPv6 addresses causes a crash. This utility is called in the data plane from the origina…
- CVE-2026-26311MEDIUMCVSS 5.9EG 5.92026-03-10
vulnerable: 1.37.0
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue create…
- CVE-2026-26330HIGHCVSS 7.5EG 7.52026-03-10
vulnerable: 1.37.0
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the respons…
Check whether github.com/envoyproxy/envoy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/envoyproxy/envoy CVEs against the assets you own.
Start Free Scan →