Envoy

Vendor:

First CVE: Apr 25, 2019 · Active for 7 years

110
Total CVEs
More Total CVEs than 99% of tracked products
13.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Envoy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2019
7 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

CVE Severity & Scoring

Envoy110 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network108 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (1.8%)
Attack Complexity
Low100 (90.9%)
High10 (9.1%)
Unknown0 (0.0%)
User Interaction
None107 (97.3%)
Unknown0 (0.0%)
Required3 (2.7%)
Privileges Required
Low10 (9.1%)
High1 (0.9%)
None99 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (110 CVEs).

110 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustio
Apr 4, 20247.570NONO
Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy'
Apr 4, 20247.570NONO
Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker
May 28, 20218.364NONO
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The imp
Oct 9, 20197.559NONO
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log for
Jun 26, 20267.534NONO
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP
Jun 26, 20267.534NONO
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filt
Jun 26, 20267.533NONO
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null poin
Jun 26, 20267.533NONO
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request
Jun 26, 20267.533NONO

Exploit Exposure

Signals from CVEs in this product scope (110 CVEs).

CISA KEV
1 CVE
0.9% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (110 CVEs).

Media Mentions

Signals from CVEs in this product scope (110 CVEs).

Top CNAs Publishing CVEs For Envoy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.117.565.4%00
1.9.017.565.4%00
1.8.017.565.4%00
1.7.117.565.4%00
1.7.017.565.4%00
1.6.017.565.4%00
1.5.017.565.4%00
1.4.017.565.4%00
1.38.017.50.8%00
1.37.056.90.3%00
1.36.017.50.4%00
1.35.028.20.4%00
1.34.015.30.2%00
1.33.017.50.4%00
1.30.319.10.7%00
1.30.017.50.7%00
1.3.017.565.4%00
1.29.619.10.7%00
1.29.117.586.8%00
1.29.017.586.8%00