CVE-2026-48090Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk) Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47220Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity High CVE-2026-47205Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47692Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream Exploitation status Not known exploited Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47207Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-48706Envoy Heap Buffer Overflow in TcpStatsdSink Exploitation status Not known exploited Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47204Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47221Envoy: Null pointer deref in internal redirects Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-48743Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity High CVE-2026-48497Envoy: Abnormal process termination in DNS UDP filter Exploitation status Not known exploited Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-48044Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion Exploitation status Not known exploited Fix YesAffected product E envoy Published 06/26/2026 Severity High CVE-2026-48042Envoy: Stack overflow in destructor of highly nested JSON Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity High CVE-2026-47778Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass) Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47775Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption Exploitation status Public exploit Fix YesAffected product E envoy Published 06/26/2026 Severity Medium CVE-2026-47774Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/17/2026 Severity High CVE-2026-26330Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly Exploitation status Not known exploited Fix YesAffected product E envoy Published 03/10/2026 Severity Medium CVE-2026-26311Envoy HTTP: filter chain execution on reset streams causing UAF crash Exploitation status Public exploit Fix YesAffected product E envoy Published 03/10/2026 Severity Medium CVE-2026-26310Crash for scoped ip address in Envoy during DNS Exploitation status Not known exploited Fix YesAffected product E envoy Published 03/10/2026 Severity Medium CVE-2026-26309Envoy has an off-by-one write in JsonEscaper::escapeString() Exploitation status Not known exploited Fix YesAffected product E envoy Published 03/10/2026 Severity Medium CVE-2026-26308Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation Exploitation status Not known exploited Fix YesAffected product E envoy Published 03/10/2026 Severity High CVE-2026-22771Envoy Extension Policy lua scripts injection causes arbitrary command execution Exploitation status Not known exploited Fix YesAffected product G gateway Published 01/12/2026 Severity High CVE-2025-66220Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 12/03/2025 Severity Medium CVE-2025-64763Envoy forwards early CONNECT data in TCP proxy mode Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 12/03/2025 Severity Low CVE-2025-64527Envoy crashes when JWT authentication is configured with the remote JWKS fetching Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 12/03/2025 Severity Medium CVE-2025-62504Envoy Lua filter use-after-free when oversized rewritten response body causes crash Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 10/16/2025 Severity Medium CVE-2025-62409Envoy allows large requests and responses to cause TCP connection pool crash Exploitation status Public exploit Fix YesAffected product E envoy Published 10/16/2025 Severity Medium CVE-2025-55162Envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag Exploitation status Public exploit Fix YesAffected product E envoy Published 09/03/2025 Severity Medium CVE-2025-54588Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults Exploitation status Not known exploited Fix YesAffected product E envoy Published 09/02/2025 Severity High CVE-2025-46821Envoy vulnerable to bypass of RBAC uri_template permission Exploitation status Not known exploited Fix YesAffected product E envoy Published 05/07/2025 Severity Medium CVE-2025-30157Envoy crashes when HTTP ext_proc processes local replies Exploitation status Public exploit Fix YesAffected product E envoy Published 03/21/2025 Severity Medium CVE-2025-25294Envoy Gateway Log Injection Vulnerability Exploitation status Not known exploited Fix YesAffected product G gateway Published 03/06/2025 Severity Medium CVE-2025-24030Envoy Admin Interface Exposed through prometheus metrics endpoint Exploitation status Not known exploited Fix Not confirmed Affected product G gateway Published 01/23/2025 Severity High CVE-2024-53271HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 12/18/2024 Severity High CVE-2024-53270HTTP/1: sending overload crashes when the request is reset beforehand in envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 12/18/2024 Severity High CVE-2024-53269Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 12/18/2024 Severity Medium CVE-2024-45806Potential manipulate `x-envoy` headers from external sources in envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 09/19/2024 Severity Medium CVE-2024-45807oghttp2 crash on OnBeginHeadersForStream in envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 09/19/2024 Severity High CVE-2024-45808Malicious log injection via access logs in envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 09/19/2024 Severity Medium CVE-2024-45809Jwt filter crash in the clear route cache with remote JWKs in envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 09/19/2024 Severity Medium CVE-2024-45810Envoy crashes for LocalReply in http async client Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 09/19/2024 Severity Medium CVE-2024-39305Envoy Proxy use after free when route hash policy is configured with cookie attributes Exploitation status Not known exploited Fix YesAffected product E envoy Published 07/01/2024 Severity Medium CVE-2024-32974Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete() Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity Medium CVE-2024-32975Envoy crashes in QuicheDataReader::PeekVarInt62Length() Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity Medium CVE-2024-32976Envoy can enter an endless loop while decompressing Brotli data with extra input Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity High CVE-2024-34362Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity Medium CVE-2024-34363Envoy can crash due to uncaught nlohmann JSON exception Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity High CVE-2024-34364Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity Medium CVE-2024-23326Envoy incorrectly accepts HTTP 200 response for entering upgrade mode Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/04/2024 Severity Medium CVE-2024-32475Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes Exploitation status Not known exploited Fix YesAffected product E envoy Published 04/18/2024 Severity High CVE-2024-30255HTTP/2: CPU exhaustion due to CONTINUATION frame flood Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 04/04/2024 Severity Medium CVE-2024-27919HTTP/2: memory exhaustion due to CONTINUATION frame flood Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 04/04/2024 Severity High CVE-2024-23322Envoy crashes when idle and request per try timeout occur within the backoff interval Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/09/2024 Severity High CVE-2024-23323Excessive CPU usage when URI template matcher is configured using regex in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/09/2024 Severity Medium CVE-2024-23324Envoy ext auth can be bypassed when Proxy protocol filter sets invalid UTF-8 metadata Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/09/2024 Severity High CVE-2024-23325Envoy crashes when using an address type that isn’t supported by the OS Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/09/2024 Severity High CVE-2024-23327Crash in proxy protocol when command type of LOCAL in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/09/2024 Severity High CVE-2023-44487Exploitation status KEV Fix Not confirmed Affected product Not confirmed Published 10/10/2023 Severity High CVE-2023-35944Envoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemes Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 07/25/2023 Severity High CVE-2023-35943Envoy vulnerable to CORS filter segfault when origin header is removed Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 07/25/2023 Severity Medium CVE-2023-35942Envoy's gRPC access log crash caused by the listener draining Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 07/25/2023 Severity Medium CVE-2023-35941Envoy vulnerable to OAuth2 credentials exploit with permanent validity Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 07/25/2023 Severity High CVE-2023-35945Envoy vulnerable to HTTP/2 memory leak in nghttp2 codec Exploitation status Public exploit Fix YesAffected product E envoy Published 07/13/2023 Severity High CVE-2023-27496Envoy may crash when a redirect url without a state param is received in the oauth filter Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 04/04/2023 Severity Medium CVE-2023-27493Envoy doesn't escape HTTP header values Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 04/04/2023 Severity High CVE-2023-27492Envoy may crash when a large request body is processed in Lua filter Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 04/04/2023 Severity Medium CVE-2023-27491Envoy forwards invalid Http2/Http3 downstream headers Exploitation status Public exploit Fix YesAffected product E envoy Published 04/04/2023 Severity Medium CVE-2023-27488Envoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received. Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 04/04/2023 Severity Medium CVE-2023-27487Envoy client may fake the header `x-envoy-original-path` Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 04/04/2023 Severity High CVE-2022-29227Use after free in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/09/2022 Severity High CVE-2022-29226Trivial authentication bypass in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/09/2022 Severity Critical CVE-2022-29228Reachable assertion in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/09/2022 Severity High CVE-2022-29225Zip bomb vulnerability in Envoy Exploitation status Public exploit Fix Not confirmed Affected product E envoy Published 06/09/2022 Severity High CVE-2022-29224Segmentation fault leading to crash in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 06/09/2022 Severity Medium CVE-2021-43826Crash when tunneling TCP over HTTP in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity High CVE-2021-43825Use-after-free in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity Medium CVE-2022-21655Incorrect handling of internal redirects results in crash in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity High CVE-2022-21654Incorrect configuration handling allows TLS session re-use without re-validation in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity High CVE-2022-21657X.509 Extended Key Usage and Trust Purposes bypass in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity Medium CVE-2022-21656X.509 subjectAltName matching bypass in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity High CVE-2022-23606Crash when a cluster is deleted in Envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity Medium CVE-2021-43824Null pointer dereference in envoy Exploitation status Not known exploited Fix Not confirmed Affected product E envoy Published 02/22/2022 Severity High CVE-2021-39206Incorrect Authorization with specially crafted requests Exploitation status Not confirmed Fix Not confirmed Affected product P pomerium Published 09/09/2021 Severity High CVE-2021-39204Excessive CPU usage in Pomerium Exploitation status Not confirmed Fix Not confirmed Affected product P pomerium Published 09/09/2021 Severity High CVE-2021-39162Incorrect handling of H2 GOAWAY + SETTINGS frames Exploitation status Not confirmed Fix Not confirmed Affected product P pomerium Published 09/09/2021 Severity High CVE-2021-32780Incorrect handling of H/2 GOAWAY followed by SETTINGS frames Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 08/24/2021 Severity High CVE-2021-32781Continued processing of requests after locally generated response Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 08/24/2021 Severity High CVE-2021-32779Incorrectly handling of URI '#fragment' element as part of the path element Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 08/24/2021 Severity High CVE-2021-32778Excessive CPU utilization when closing HTTP/2 streams Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 08/24/2021 Severity Medium CVE-2021-32777Incorrect concatenation of multiple value request headers in ext-authz extension Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 08/24/2021 Severity High CVE-2021-29492Bypass of path matching rules using escaped slash characters Exploitation status Not confirmed Fix Not confirmed Affected product E envoy Published 05/28/2021 Severity High CVE-2021-29258Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 05/20/2021 Severity Unknown CVE-2021-28683Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 05/20/2021 Severity Unknown CVE-2021-28682Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 05/20/2021 Severity Unknown CVE-2021-21378JWT authentication bypass with unknown issuer token Exploitation status Not confirmed Fix YesAffected product E envoy Published 03/11/2021 Severity High CVE-2020-35470Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 12/15/2020 Severity Unknown CVE-2020-35471Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 12/15/2020 Severity Unknown CVE-2020-25018Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 10/01/2020 Severity Unknown CVE-2020-25017Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 10/01/2020 Severity Unknown CVE-2020-15104TLS Validation Vulnerability in Envoy Exploitation status Not confirmed Fix YesAffected product E envoy Published 07/14/2020 Severity Medium CVE-2020-12605Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 07/01/2020 Severity Unknown