envoyproxy
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 98 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 9, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Envoy global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Envoy HTTP: filter chain execution on reset streams causing UAF crash
Envoy has an off-by-one write in JsonEscaper::escapeString()
Envoy has an RBAC Header Validation Bypass via Multi-Value Header Concatenation
Crash for scoped ip address in Envoy during DNS
Envoy Extension Policy lua scripts injection causes arbitrary command execution
Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Envoy forwards early CONNECT data in TCP proxy mode
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Envoy Lua filter use-after-free when oversized rewritten response body causes crash
Monitor envoyproxy in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.