VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Envoyproxy
>
Envoy
> 1.25.9
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2024-09-20
CVE-2024-45806
Authorization Bypass Through User-Controlled Key vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
CWE-639
6.5
6.5
2024-09-20
CVE-2024-45808
Improper Encoding or Escaping of Output vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
CWE-116
6.5
6.5
2024-09-20
CVE-2024-45810
Unspecified vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
7.5
7.5
2024-06-04
CVE-2024-23326
HTTP Request Smuggling vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy
CWE-444
8.2
8.2
2024-06-04
CVE-2024-32974
Use After Free vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy
CWE-416
7.5
7.5
2024-06-04
CVE-2024-32975
Integer Underflow (Wrap or Wraparound) vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy
CWE-191
7.5
7.5
2024-06-04
CVE-2024-32976
Infinite Loop vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy
CWE-835
7.5
7.5
2024-06-04
CVE-2024-34362
Use After Free vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
high complexity
envoyproxy
CWE-416
5.9
5.9
2024-06-04
CVE-2024-34364
Out-of-bounds Write vulnerability in Envoyproxy Envoy
Envoy is a cloud-native, open source edge and service proxy.
network
low complexity
envoyproxy
CWE-787
6.5
6.5
2023-10-10
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
network
low complexity
ietf
nghttp2
netty
envoyproxy
eclipse
caddyserver
golang
f5
apache
apple
grpc
microsoft
nodejs
dena
facebook
amazon
debian
kazu-yamamoto
istio
varnish-cache-project
traefik
projectcontour
linkerd
linecorp
redhat
fedoraproject
netapp
akka
konghq
jenkins
openresty
cisco
7.5
7.5