PatchSiren

envoyproxy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73553

CVE-2026-73553 is a high-severity vulnerability in Envoy, a cloud-native edge and service proxy. When the ignore_path_parameters_in_path_matching option is enabled, Envoy's router strips semicolon suffixes from paths before matching, but the RBAC (Role-Based Access Control) url_path matcher evaluates the raw path. This inconsistency allows an unauthenticated client to bypass path-based authorization. For [truncated]

MEDIUM envoyproxy CVE published 2026-09-21

CVE-2026-73551

CVE-2026-73551 is a path confusion issue in Envoy's URL normalization. A remote client can cause path confusion and bypass path-based security policy due to Envoy not recognizing dot and dotdot path segments with semicolon parameters. This issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. The vulnerability allows an attacker to manipulate URL paths, potentially leading to unauthorized [truncated]

MEDIUM Envoyproxy CVE published 2026-09-21

CVE-2026-73511

CVE-2026-73511 is a vulnerability in Envoy, an open-source edge and service proxy. The issue arises from Envoy's path matching mechanism, which does not align with the behavior of servlet backends like Apache Tomcat. Specifically, Envoy's ignore_path_parameters_in_path_matching option can lead to a remote client bypassing security checks by exploiting semicolon matrix parameters in URLs. This bypass requi [truncated]

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73552

CVE-2026-73552 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The issue allows a downstream client to bypass intended RBAC policies by crafting specific HTTP requests. This CVE was published on 2026-09-21T20:17:28.900Z and was last modified on 2026-10-05T14:35:24.370Z. Affected product deployments should be assessed for exposure, especially those using Envoy versions pri [truncated]

HIGH envoyproxy CVE published 2026-09-21

CVE-2026-73550

CVE-2026-73550 is a high-severity vulnerability in Envoy, a cloud-native edge and service proxy. An unauthenticated client can exploit this issue by using HPACK indexing to submit many references to a large Host value across a bounded number of streams, causing the proxy to be out-of-memory killed. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

MEDIUM Envoyproxy CVE published 2026-09-21

CVE-2026-73549

CVE-2026-73549 is a vulnerability in Envoy, an open-source edge and service proxy, which can cause a process termination due to improper handling of scoped IPv6 addresses in the Utility::copyInternetAddressAndPort and QUIC client-address paths. This issue affects Envoy versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, particularly in ORIGINAL_DST transparent-proxy deployments or QUIC connection paths [truncated]

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73548

CVE-2026-73548 debrief based on the supplied source corpus. The CVE record was published on 2026-09-21T20:17:28.397Z and has not been modified since then. Envoy, an open source edge and service proxy, has a vulnerability that allows an unauthenticated HTTP/2 client to smuggle a complete HTTP/1.1 request in extended CONNECT data, potentially leading to response smuggling. This issue affects Envoy versions [truncated]

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73547

CVE-2026-73547 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The vulnerability exists in the ext_authz filter and can cause a crash when processing a path-less CONNECT request with query-parameter mutation. This issue affects Envoy versions prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Defenders and administrators of Envoy deployments that use ext_authz filter and query [truncated]

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73546

CVE-2026-73546 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The vulnerability affects Envoy's /stats?format=html admin endpoint, which can be exploited by an attacker to execute script with the admin interface's origin and issue privileged same-origin requests. The issue is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

HIGH envoyproxy CVE published 2026-09-21

CVE-2026-73513

CVE-2026-73513 is a high-severity vulnerability in Envoy, an open-source edge and service proxy. The issue arises from Envoy's optional oghttp2 upstream HTTP/2 codec accepting a response trailer HEADERS frame without END_STREAM, potentially leading to a crash. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Affected product deployments should be assessed for exposure, an [truncated]

HIGH Envoyproxy CVE published 2026-09-21

CVE-2026-73512

CVE-2026-73512 is a high-severity vulnerability in Envoy, a cloud-native edge and service proxy. The issue arises from Envoy's HttpDatagramHandler caching the current RequestDecoder when Capsule Protocol is enabled. During stream recreation, such as an internal redirect, the ActiveStream and EnvoyQuicServerStream are updated, but the handler's cached pointer is not. This can lead to a process crash when a [truncated]

MEDIUM Envoyproxy CVE published 2026-09-21

CVE-2026-50572

CVE-2026-50572 is a use-after-free vulnerability in Envoy's HTTP external-authorization client. When a request is rejected, the client can retain a stale request callback. Later, when RawHttpClientImpl::onSuccess processes the authorization response, it can invoke callbacks_ after the callback owner has been destroyed, causing a process crash under production traffic. This issue affects Envoy versions pri [truncated]

MEDIUM envoyproxy CVE published 2026-09-21

CVE-2026-48521

CVE-2026-48521 is a vulnerability in Envoy, an open-source edge and service proxy, that can cause a worker crash when handling HTTP/3 traffic with specific configurations. The issue arises from a null pointer dereference in the ProdClusterManagerFactory::allocateConnPool function. This vulnerability is fixed in Envoy versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

MEDIUM envoyproxy CVE published 2026-09-14

CVE-2026-53718

CVE-2026-53718 is a vulnerability in Envoy Gateway, an open-source project for managing Envoy Proxy. The issue allows an HTTPRoute to reference a backend resource in another namespace without proper authorization, violating the Gateway API's cross-namespace authorization model. This vulnerability is fixed in versions 1.7.4 and 1.8.1. Affected product deployments should be reviewed for exposure, and defend [truncated]

MEDIUM envoyproxy CVE published 2026-09-14

CVE-2026-53715

CVE-2026-53715 is a timing-dependent, cross-tenant control-plane denial of service vulnerability in Envoy Gateway. An attacker with pod-network access to unauthenticated port 18002 and tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a per-request reader overlaps a writer, causing the controller process to terminate.

MEDIUM Envoyproxy CVE published 2026-06-26

CVE-2026-48497

CVE-2026-48497 is a medium-severity vulnerability affecting Envoy, an open-source edge and service proxy. The vulnerability occurs in the UDP DNS filter and can cause abnormal process termination when a query with a name of 255 octets is processed. This happens because the filter incorrectly assumes the query name must be strictly less than 255 octets, contradicting the DNS specification (RFC 1035). The i [truncated]

HIGH envoyproxy CVE published 2026-06-26

CVE-2026-48042

CVE-2026-48042 is a high-severity vulnerability affecting Envoy, an open-source edge and service proxy. The vulnerability occurs in the destructor of JSON objects, which can lead to a stack overflow when dealing with deeply nested objects, approximately 100,000 levels deep. This issue was addressed in Envoy versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1. The vulnerability has a CVSS score of 7.5 and is clas [truncated]

MEDIUM Envoyproxy CVE published 2026-06-26

CVE-2026-47775

CVE-2026-47775 is a vulnerability in Envoy's OAuth2 HTTP filter. The encrypt()/decrypt() functions use AES-256-CBC without an authentication tag, creating a padding oracle. An attacker can recover the plaintext PKCE code_verifier in ~6,200 requests and exchange it for a stolen authorization code to obtain the victim's access token. This issue affects Envoy versions prior to 1.35.11, 1.36.7, 1.37.3, and 1. [truncated]

HIGH envoyproxy CVE published 2026-06-17

CVE-2026-47774

CVE-2026-47774 is a high-severity vulnerability in Envoy's HTTP/2 downstream request processing. An unauthenticated remote client can trigger excessive memory consumption, potentially resulting in OOM termination of the Envoy process and denial of service. This issue arises from a combination of two behaviors: incomplete accounting of cookie header bytes during request header size validation and HPACK hea [truncated]

HIGH Envoyproxy CVE published 2026-01-12

CVE-2026-22771

CVE-2026-22771 is a high-severity vulnerability in Envoy Gateway, a project for managing Envoy Proxy. The vulnerability allows EnvoyExtensionPolicy Lua scripts executed by Envoy proxy to leak the proxy's credentials. These credentials can be used to communicate with the control plane and gain access to all secrets used by Envoy proxy, including TLS private keys and credentials for downstream and upstream [truncated]

HIGH envoyproxy CVE published 2025-07-22

CVE-2023-35945

CVE-2023-35945 is publicly documented by CISA in a CSAF advisory for Schneider Electric EcoStruxure Power Operation (EPO). The supplied advisory ties the issue to EPO 2022 and EPO 2024 and describes a denial-of-service outcome driven by a memory leak/memory exhaustion condition. Because the affected product lines are industrial control system software, availability impact should be treated as operationall [truncated]