Exposição de Envoy

Reverse proxies
69
score de exposição
90.631
sites usam
0
em exploração
1
críticos
Análise Vexday

Com 78 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Envoy apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica ausência de exploração confirmada em campo até o momento. Ainda assim, o escore EPSS de 0,8781 associado a CVE-2024-30255 sinaliza probabilidade elevada de exploração futura, merecendo atenção prioritária nas equipes de resposta. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade com potencial de impacto severo em tempo de execução, especialmente em proxies de alto throughput como o Envoy. A presença de apenas uma CVE crítica e duas ocorrências nos últimos 90 dias sugere ritmo moderado de descobertas recentes, mas o perfil de risco não deve ser subestimado dado o valor EPSS observado.

CVEs

92 resultados
CVE-2021-43826HIGHCrash when tunneling TCP over HTTP in EnvoyEPSS 1.1%CVE-2022-23606MEDIUMCrash when a cluster is deleted in EnvoyEPSS 1.0%CVE-2022-29224MEDIUMSegmentation fault leading to crash in EnvoyEPSS 1.0%CVE-2026-47774HIGHEnvoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplificationEPSS 1.0%CVE-2021-32779HIGHIncorrectly handling of URI '#fragment' element as part of the path elementEPSS 0.9%CVE-2023-35942MEDIUMEnvoy's gRPC access log crash caused by the listener drainingEPSS 0.9%CVE-2021-43825MEDIUMUse-after-free in EnvoyEPSS 0.9%CVE-2023-27491MEDIUMEnvoy forwards invalid Http2/Http3 downstream headersEPSS 0.9%CVE-2023-35941HIGHEnvoy vulnerable to OAuth2 credentials exploit with permanent validityEPSS 0.8%CVE-2024-21877HIGHInsecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225EPSS 0.8%CVE-2023-27496MEDIUMEnvoy may crash when a redirect url without a state param is received in the oauth filterEPSS 0.8%CVE-2024-23325HIGHEnvoy crashes when using an address type that isn’t supported by the OSEPSS 0.8%CVE-2023-27488MEDIUMEnvoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.EPSS 0.7%CVE-2023-35944HIGHEnvoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemesEPSS 0.7%CVE-2024-53270HIGHHTTP/1: sending overload crashes when the request is reset beforehand in envoyEPSS 0.7%CVE-2024-23327HIGHCrash in proxy protocol when command type of LOCAL in EnvoyEPSS 0.7%CVE-2024-32974MEDIUMEnvoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()EPSS 0.7%CVE-2024-32975MEDIUMEnvoy crashes in QuicheDataReader::PeekVarInt62Length()EPSS 0.7%CVE-2023-27492MEDIUMEnvoy may crash when a large request body is processed in Lua filterEPSS 0.7%CVE-2024-32475HIGHEnvoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytesEPSS 0.7%