Envoyproxy maintains a focused but strategically critical proxy and gateway product line that sits deep in service-mesh and load-balancing architectures across cloud-native deployments. Despite a narrow product portfolio, its prominence in the vulnerability landscape reflects the central role these products play in request routing and traffic management for containerized and microservice-oriented infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including use-after-free conditions, NULL-pointer dereferences, improper input validation, and uncontrolled resource consumption—exposures characteristic of a high-performance C++ codebase operating at the network edge. Defenders should treat updates to this vendor as high-priority across any deployment that fronts internal or external traffic, since a flaw in the proxy tier can compromise entire application stacks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Envoyproxy over time
Signals from CVEs in this vendor scope (113 CVEs).
113 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2024-30255HIGH Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustio | Apr 4, 2024 | 7.5 | 70 | NO | NO |
CVE-2024-27919HIGH Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy' | Apr 4, 2024 | 7.5 | 70 | NO | NO |
CVE-2021-29492HIGH Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker | May 28, 2021 | 8.3 | 64 | NO | NO |
CVE-2019-15226HIGH Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The imp | Oct 9, 2019 | 7.5 | 59 | NO | NO |
CVE-2026-47220HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log for | Jun 26, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-48706HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP | Jun 26, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-47204HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filt | Jun 26, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-47221HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null poin | Jun 26, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-48743HIGH Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request | Jun 26, 2026 | 7.5 | 33 | NO | NO |
Signals from CVEs in this vendor scope (113 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Envoyproxy.
Media articles that mention a CVE ID that affects a product developed by Envoyproxy — matched by CVE ID, not by vendor name.