<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Envoy (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/envoy.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/envoy-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Envoy (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41246 – Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41246</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41246</strong></p>
  <p>Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32811 – Heimdall is a cloud native Identity Aware Proxy and Access Control Decision serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32811</guid>
    <pubDate>Fri, 20 Mar 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32811</strong></p>
  <p>Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha through 0.17.10, wrong encoding of the query URL string allows rules with non-wildcard path expressions to be bypassed. Envoy splits the requested URL into parts, and sends the parts individually to Heimdall. Although query and path are…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23941 – Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23941</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23941</strong></p>
  <p>Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.  This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.  The server does not reject or normalize duplicate Content-Length headers. The earliest Content-Le…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26308 – Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26308</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26308</strong></p>
  <p>Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. Thi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26205 – opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26205</guid>
    <pubDate>Thu, 19 Feb 2026 20:25:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26205</strong></p>
  <p>opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority components, and therefore dropping them from the parsed path. This creates a path inte…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22771 – Envoy Gateway is an open source project for managing Envoy Proxy as a standalone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22771</guid>
    <pubDate>Mon, 12 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22771</strong></p>
  <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS privat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64171 – MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64171</guid>
    <pubDate>Thu, 06 Nov 2025 01:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64171</strong></p>
  <p>MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62409 – Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62409</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62409</strong></p>
  <p>Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP connection pool crashes due to flow control management in Envoy. It will happen when the connection is closing but upstream data is still coming, resulting in a buffer watermark callback nullptr reference. The vulnerability impacts TCP…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54588 – Envoy is an open source L7 proxy and communication bus designed for large modern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54588</guid>
    <pubDate>Wed, 03 Sep 2025 00:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54588</strong></p>
  <p>Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Versions 1.34.0 through 1.34.4 and 1.35.0 contain a use-after-free (UAF) vulnerability in the DNS cache, causing abnormal process termination. The vulnerability is in Envoy's Dynamic Forward Proxy implementation, occurring when a completion callback for a DNS resolution triggers new DN…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23556 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23556</guid>
    <pubDate>Mon, 03 Mar 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23556</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in netbitsolutions Push Envoy Notifications push-envoy allows Reflected XSS.This issue affects Push Envoy Notifications: from n/a through <= 1.0.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0752 – A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0752</guid>
    <pubDate>Tue, 28 Jan 2025 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0752</strong></p>
  <p>A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24030 – Envoy Gateway is an open source project for managing Envoy Proxy as a standalone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24030</guid>
    <pubDate>Thu, 23 Jan 2025 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24030</strong></p>
  <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy config…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-419</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53271 – Envoy is a cloud-native high-performance edge/middle/service proxy. In affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53271</guid>
    <pubDate>Wed, 18 Dec 2024 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53271</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy  does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgrade. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53270 – Envoy is a cloud-native high-performance edge/middle/service proxy. In affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53270</guid>
    <pubDate>Wed, 18 Dec 2024 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53270</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is nullptr, only onMessageBeginImpl() is called. However, the `onMessageBeginImpl` will directly return ok status if the stream is already reset leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45807 – Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45807</guid>
    <pubDate>Fri, 20 Sep 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45807</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the `oghttp2` by default. The impact of this issue is that envoy will crash. This issue has been addressed in release version 1.31.2. All users are advised to upgrad…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21881 – Inadequate Encryption Strength vulnerability allow an authenticated attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21881</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21881</strong></p>
  <p>Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21880 – Improper Neutralization of Special Elements used in a Command ('Command Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21880</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21880</strong></p>
  <p>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21879 – Improper Neutralization of Special Elements used in a Command ('Command Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21879</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21879</strong></p>
  <p>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21878 – Improper Neutralization of Special Elements used in a Command ('Command Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21878</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21878</strong></p>
  <p>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21876 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21876</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21876</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37307 – Cilium is a networking, observability, and security solution with an eBPF-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37307</guid>
    <pubDate>Thu, 13 Jun 2024 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37307</strong></p>
  <p>Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag set) against Cilium deployments with the Envoy proxy enabled. Users of the TLS inspection, Ingress with TLS termination,…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34363 – Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34363</guid>
    <pubDate>Tue, 04 Jun 2024 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34363</strong></p>
  <p>Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32976 – Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32976</guid>
    <pubDate>Tue, 04 Jun 2024 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32976</strong></p>
  <p>Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32475 – Envoy is a cloud-native, open source edge and service proxy. When an upstream TL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32475</guid>
    <pubDate>Thu, 18 Apr 2024 15:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32475</strong></p>
  <p>Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process. Envoy does not gracefully handle an error when setting SNI for outbound TLS connection. The error can occur when Envoy attempts to use the `host`/`:…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-253</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27919 – Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27919</guid>
    <pubDate>Thu, 04 Apr 2024 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27919</strong></p>
  <p>Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an attacker to send an sequence of CONTINUATION frames without the END_HEADERS bit set causing unlimited memory consumption.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23327 – Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23327</guid>
    <pubDate>Fri, 09 Feb 2024 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23327</strong></p>
  <p>Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue has been addressed in releases 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are ad…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23325 – Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23325</guid>
    <pubDate>Fri, 09 Feb 2024 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23325</strong></p>
  <p>Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address.  It is valid for a client to present its IPv6 address to a target serv…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23324 – Envoy is a high-performance edge/middle/service proxy. External authentication c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23324</guid>
    <pubDate>Fri, 09 Feb 2024 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23324</strong></p>
  <p>Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known wor…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23322 – Envoy is a high-performance edge/middle/service proxy. Envoy will crash when cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23322</guid>
    <pubDate>Fri, 09 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23322</strong></p>
  <p>Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: 1. hedge_on_per_try_timeout is enabled, 2. per_try_idle_timeout is enabled (it can only be done in configuration), 3. per-try-timeout is enabled, either through headers or configuration and its value is equal, or within the ba…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35944 – Envoy is an open source edge and service proxy designed for cloud-native applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35944</guid>
    <pubDate>Tue, 25 Jul 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35944</strong></p>
  <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Envoy allows mixed-case schemes in HTTP/2, however, some internal scheme checks are case-sensitive. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, this can lead to the rejection of requests with mixed-case schemes such as `htTp` or `htTps`, or the bypassing of some requests such as `https` in u…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35941 – Envoy is an open source edge and service proxy designed for cloud-native applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35941</guid>
    <pubDate>Tue, 25 Jul 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35941</strong></p>
  <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able to construct credentials with permanent validity in some specific scenarios. This is caused by the some rare scenarios in which HMAC payload can be always valid in OAuth2 filter's check. Versions 1.27.0, 1.26.4, 1.25.9, 1…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35945 – Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35945</guid>
    <pubDate>Thu, 13 Jul 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35945</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The err…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2816 – Consul and Consul Enterprise allowed any user with service:write permissions to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2816</guid>
    <pubDate>Fri, 02 Jun 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2816</strong></p>
  <p>Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27493 – Envoy is an open source edge and service proxy designed for cloud-native applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27493</guid>
    <pubDate>Tue, 04 Apr 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27493</strong></p>
  <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, Envoy does not sanitize or escape request properties when generating request headers. This can lead to characters that are illegal in header values to be sent to the upstream service. In the worst case, it can cause upstream service to interpret the…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27487 – Envoy is an open source edge and service proxy designed for cloud-native applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27487</guid>
    <pubDate>Tue, 04 Apr 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27487</strong></p>
  <p>Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, the client may bypass JSON Web Token (JWT) checks and forge fake original paths. The header `x-envoy-original-path` should be an internal header, but Envoy does not remove this header from the request at the beginning of request processing when it is…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31045 – Istio is an open platform to connect, manage, and secure microservices. In affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31045</guid>
    <pubDate>Thu, 09 Jun 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31045</strong></p>
  <p>Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29228 – Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29228</guid>
    <pubDate>Thu, 09 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29228</strong></p>
  <p>Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions. continueDecoding() shouldn’t ever be called from filters after a local reply has been sent. Users are advised to upgrade. There are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29227 – Envoy is a cloud-native high-performance edge/middle/service proxy. In versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29227</guid>
    <pubDate>Thu, 09 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29227</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request Envoy sends a local reply when the redirect headers are processed, the downstream state indicates that the downstream str…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29226 – Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29226</guid>
    <pubDate>Thu, 09 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29226</strong></p>
  <p>Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any acce…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29225 – Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 seco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29225</guid>
    <pubDate>Thu, 09 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29225</strong></p>
  <p>Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21656 – Envoy is an open source edge and service proxy, designed for cloud-native applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21656</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21656</strong></p>
  <p>Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjectAltNames. This processing allows, for example, an rfc822Name or uniformResourceIndicator to be authenticated as a domain name. This confusion allows for the by…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21655 – Envoy is an open source edge and service proxy, designed for cloud-native applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21655</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21655</strong></p>
  <p>Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround turn off internal redirects if direct response entries are configured on the same listener.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21654 – Envoy is an open source edge and service proxy, designed for cloud-native applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21654</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21654</strong></p>
  <p>Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used. Users are advised to upgrade.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43826 – Envoy is an open source edge and service proxy, designed for cloud-native applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43826</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43826</strong></p>
  <p>Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43824 – Envoy is an open source edge and service proxy, designed for cloud-native applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43824</guid>
    <pubDate>Tue, 22 Feb 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43824</strong></p>
  <p>Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only workaround is to not use regex in the JWT filter. Users are advised to upgrade.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39206 – Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39206</guid>
    <pubDate>Thu, 09 Sep 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39206</strong></p>
  <p>Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or authorization policy decisions. With specially crafted requests, incorrect authorization or routing decisions may be made by Pomerium. Pomerium v0.14.8 and v0.15.1 contain an upgraded…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39204 – Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39204</guid>
    <pubDate>Thu, 09 Sep 2021 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39204</strong></p>
  <p>Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting of HTTP/2 streams with excessive complexity. This can lead to high CPU utilization when a large number of streams are reset. This can result in a DoS condition. Pomerium versions 0.14.8 and 0.15.1 contain an upgraded envoy binary with this vulnerability patched.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39162 – Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39162</guid>
    <pubDate>Thu, 09 Sep 2021 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39162</strong></p>
  <p>Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if an H/2 GOAWAY and SETTINGS frame are received in the same IO event. This can lead to a DoS in the presence of untrusted *upstream* servers. 0.15.1 contains an upgraded envoy binary with this vulnerability patched. If only trusted upstreams are configured, there is not substantial…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32781 – Envoy is an open source L7 proxy and communication bus designed for large modern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32781</guid>
    <pubDate>Tue, 24 Aug 2021 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32781</strong></p>
  <p>Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32780 – Envoy is an open source L7 proxy and communication bus designed for large modern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32780</guid>
    <pubDate>Tue, 24 Aug 2021 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32780</strong></p>
  <p>Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions Envoy transitions a H/2 connection to the CLOSED state when it receives a GOAWAY frame without any streams outstanding. The connection state is transitioned to DRAINING when it receives a SETTING frame with the SETTINGS_MAX_CONCURRENT_STREAMS parameter set to 0. Re…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32779 – Envoy is an open source L7 proxy and communication bus designed for large modern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32779</guid>
    <pubDate>Tue, 24 Aug 2021 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32779</strong></p>
  <p>Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with an RBAC filter for authorization or similar mechanism with an explicit case of a final "/admin" path element, or is using a negative assertion with final path…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-551</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32777 – Envoy is an open source L7 proxy and communication bus designed for large modern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32777</guid>
    <pubDate>Tue, 24 Aug 2021 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32777</strong></p>
  <p>Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization service it must merge multiple value headers according to the HTTP spec. However, only the last header value is sent. This may allow specifically crafted requests to bypass authorizat…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-551</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32783 – Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32783</guid>
    <pubDate>Fri, 23 Jul 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32783</strong></p>
  <p>Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy remotely (a denial of service), or to expose the existence of any Secret that Envoy is using for its c…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32574 – HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS conf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32574</guid>
    <pubDate>Sat, 17 Jul 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32574</strong></p>
  <p>HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name. Fixed in 1.8.14, 1.9.8, and 1.10.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25755 – An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25755</guid>
    <pubDate>Wed, 16 Jun 2021 19:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25755</strong></p>
  <p>An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary commands via the force parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25754 – An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25754</guid>
    <pubDate>Wed, 16 Jun 2021 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25754</strong></p>
  <p>An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. Attempts to change the user password via passwd or other tools have…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25753 – An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25753</guid>
    <pubDate>Wed, 16 Jun 2021 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25753</strong></p>
  <p>An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29492 – Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29492</guid>
    <pubDate>Fri, 28 May 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29492</strong></p>
  <p>Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server could then decode slash sequences and normalize path and provide an attacker ac…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29258 – An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29258</guid>
    <pubDate>Thu, 20 May 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29258</strong></p>
  <p>An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28683 – An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28683</guid>
    <pubDate>Thu, 20 May 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28683</strong></p>
  <p>An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28682 – An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28682</guid>
    <pubDate>Thu, 20 May 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28682</strong></p>
  <p>An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21378 – Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21378</guid>
    <pubDate>Thu, 11 Mar 2021 03:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21378</strong></p>
  <p>Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due to a mistake in implementation. Envoy's JWT Authentication filter can be configu…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35471 – Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35471</guid>
    <pubDate>Tue, 15 Dec 2020 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35471</strong></p>
  <p>Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35470 – Envoy before 1.16.1 logs an incorrect downstream address because it considers on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35470</guid>
    <pubDate>Tue, 15 Dec 2020 01:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35470</strong></p>
  <p>Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25018 – Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25018</guid>
    <pubDate>Thu, 01 Oct 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25018</strong></p>
  <p>Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25017 – Envoy through 1.15.0 only considers the first value when multiple header values ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25017</guid>
    <pubDate>Thu, 01 Oct 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25017</strong></p>
  <p>Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15127 – In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad acto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15127</guid>
    <pubDate>Wed, 05 Aug 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15127</strong></p>
  <p>In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flipping the readiness endpoint to false, which removes Envoy from the routing pool. When running Envoy…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8663 – Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8663</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8663</strong></p>
  <p>Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12605 – Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12605</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12605</strong></p>
  <p>Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12604 – Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12604</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12604</strong></p>
  <p>Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12603 – Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12603</guid>
    <pubDate>Wed, 01 Jul 2020 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12603</strong></p>
  <p>Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8661 – CNCF Envoy through 1.13.0 may consume excessive amounts of memory when respondin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8661</guid>
    <pubDate>Wed, 04 Mar 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8661</strong></p>
  <p>CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8659 – CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8659</guid>
    <pubDate>Wed, 04 Mar 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8659</strong></p>
  <p>CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18838 – An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18838</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18838</strong></p>
  <p>An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18802 – An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18802</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18802</strong></p>
  <p>An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18801 – An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18801</guid>
    <pubDate>Fri, 13 Dec 2019 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18801</strong></p>
  <p>An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18836 – Envoy 1.12.0 allows a remote denial of service because of resource loops, as dem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18836</guid>
    <pubDate>Mon, 11 Nov 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18836</strong></p>
  <p>Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15226 – Upon receiving each incoming request header data, Envoy will iterate over existi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15226</guid>
    <pubDate>Wed, 09 Oct 2019 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15226</strong></p>
  <p>Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1.11.1 for HTTP/1.x traffic and all versions of Envoy for HTTP/2 traffic had O(n^2) performance characteristics. A remote attacker may craft a request that stays below the maximum…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15225 – In Envoy through 1.11.1, users may configure a route to match incoming path head...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15225</guid>
    <pubDate>Mon, 19 Aug 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15225</strong></p>
  <p>In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to result in a denial of service (memory consumption). This is a related issue to CVE-2019-14993.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12995 – Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 termina...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12995</guid>
    <pubDate>Fri, 28 Jun 2019 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12995</strong></p>
  <p>Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.cc segmentation fault.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9900 – When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9900</guid>
    <pubDate>Thu, 25 Apr 2019 15:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9900</strong></p>
  <p>When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-7678 – A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7678</guid>
    <pubDate>Sat, 09 Feb 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-7678</strong></p>
  <p>A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7676 – A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7676</guid>
    <pubDate>Sat, 09 Feb 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7676</strong></p>
  <p>A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7676">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
