envoyproxy
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 113 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 9, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)
Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message
Envoy Heap Buffer Overflow in TcpStatsdSink
Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes
Envoy: Null pointer deref in internal redirects
Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
Envoy: Abnormal process termination in DNS UDP filter
Monitor envoyproxy in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.