Vulnerabilities > Envoyproxy > Envoy > 1.12.5

DATE CVE VULNERABILITY TITLE RISK
2024-09-20 CVE-2024-45806 Authorization Bypass Through User-Controlled Key vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-639
6.5
2024-09-20 CVE-2024-45808 Improper Encoding or Escaping of Output vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy CWE-116
6.5
2024-09-20 CVE-2024-45810 Unspecified vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
7.5
2024-06-04 CVE-2024-23326 HTTP Request Smuggling vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy CWE-444
8.2
2024-06-04 CVE-2024-32974 Use After Free vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy CWE-416
7.5
2024-06-04 CVE-2024-32975 Integer Underflow (Wrap or Wraparound) vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy CWE-191
7.5
2024-06-04 CVE-2024-34362 Use After Free vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
high complexity
envoyproxy CWE-416
5.9
2024-06-04 CVE-2024-34364 Out-of-bounds Write vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy CWE-787
6.5
2023-07-13 CVE-2023-35945 Incomplete Cleanup vulnerability in multiple products
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy nghttp2 CWE-459
7.5
2023-04-04 CVE-2023-27493 HTTP Request Smuggling vulnerability in Envoyproxy Envoy
Envoy is an open source edge and service proxy designed for cloud-native applications.
network
low complexity
envoyproxy CWE-444
critical
9.1