Envoy
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 47 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 19, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
Envoy Heap Buffer Overflow in TcpStatsdSink
Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
Envoy: Null pointer deref in internal redirects
Envoy: Abnormal process termination in DNS UDP filter
Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
Monitor Envoy in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.