Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Envoyproxy

First CVE: Apr 25, 2019Active for: 7 yearsTotal CVEs: 113
71.8
VTI Score
TOP TARGET

Envoyproxy maintains a focused but strategically critical proxy and gateway product line that sits deep in service-mesh and load-balancing architectures across cloud-native deployments. Despite a narrow product portfolio, its prominence in the vulnerability landscape reflects the central role these products play in request routing and traffic management for containerized and microservice-oriented infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including use-after-free conditions, NULL-pointer dereferences, improper input validation, and uncontrolled resource consumption—exposures characteristic of a high-performance C++ codebase operating at the network edge. Defenders should treat updates to this vendor as high-priority across any deployment that fronts internal or external traffic, since a flaw in the proxy tier can compromise entire application stacks. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
113
Total CVEs
More Total CVEs than 99% of tracked vendors
7.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Envoyproxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2019
7 years ago
Most Recent CVE
Jun 26, 2026
29 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (113 CVEs).

113 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2024-30255HIGH
Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustio
Apr 4, 20247.570NONO
CVE-2024-27919HIGH
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy'
Apr 4, 20247.570NONO
CVE-2021-29492HIGH
Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker
May 28, 20218.364NONO
CVE-2019-15226HIGH
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The imp
Oct 9, 20197.559NONO
CVE-2026-47220HIGH
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log for
Jun 26, 20267.534NONO
CVE-2026-48706HIGH
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP
Jun 26, 20267.533NONO
CVE-2026-47204HIGH
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filt
Jun 26, 20267.533NONO
CVE-2026-47221HIGH
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null poin
Jun 26, 20267.533NONO
CVE-2026-48743HIGH
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request
Jun 26, 20267.533NONO
View all 113 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products113 CVEs
23%
66%
10%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network110 (97.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (2.7%)
Attack Complexity
Low103 (91.2%)
High10 (8.8%)
Unknown0 (0.0%)
User Interaction
None110 (97.3%)
Unknown0 (0.0%)
Required3 (2.7%)
Privileges Required
Low11 (9.7%)
High1 (0.9%)
None101 (89.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (113 CVEs).

CISA KEV
1 CVE
0.9% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Envoyproxy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Envoyproxy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Envoyproxy's Products

View all 2 CNAs →

Top CWEs