Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.30% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-only close) but still carries a nonzero Content-Length into a complete… | |
| Analizada | Alta (7.5) | 0.61% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionally long statistic names (e.g., >16KiB).… | |
| Analizada | Alta (7.5) | 0.40% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete… | |
| Analizada | Alta (7.5) | 0.49% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability has been identified in Envoy's zstd decompressor implementation (ZstdDecompressorImpl). When zstd decompression is enabled, processing a specially crafted,… | |
| Analizada | Alta (7.5) | 0.56% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, destructor of JSON Object results in stack overflow when deeply O(100K) nested objects are present. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1. | |
| Analizada | Media (4.4) | 0.21% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySubjectAltName where the extracted DNS SAN string is cast to a C-style string using .c_str() before being passed to the… | |
| Analizada | Media (6.8) | 0.22% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEAD). The /callback endpoint returns HTTP 302 on successful decryption… | |
| Analizada | Media (4.3) | 0.22% | — | Envoyproxy Envoy | 26/6/2026 | 27/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch between bytes written and the length field in the header. This can… | |
| Analizada | Alta (7.5) | 0.45% | — | Envoyproxy Envoy | 26/6/2026 | 27/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vulnerability when handling HTTP 303 (See Other) internal redirects for body-less non-GET/HEAD requests. When a POST, PUT,… | |
| Analizada | Media (6.5) | 0.44% | — | Envoyproxy Envoy | 26/6/2026 | 27/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC message containing multiple, specially crafted ProcessingResponse messages. This can occur when the first response in the… | |
| Modificada | Alta (7.5) | 0.45% | — | Envoyproxy Envoy | 26/6/2026 | 29/6/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null pointer dereference / segfault) when a Connect protocol request (Content-Type: application/connect+proto or… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Zaproxy ZAPAIZaproxy Viewstate Add-onAI | 26/6/2026 | 14/7/2026 | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The… | |
| Aplazada | Alta (8.3) | 0.39% | — | OhifAIOhif DicomwebproxyAIOhif DicomjsonAI | 25/6/2026 | 26/6/2026 | Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server.… | |
| Analizada | Alta (7.5) | 0.29% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 24/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it rebuilds the body with… | |
| Analizada | Media (6.9) | 0.38% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 26/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result,… | |
| Analizada | Alta (7.5) | 0.39% | — | Proxysql | 19/6/2026 | 11/8/2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented read-only contract for MySQL targets. The tool validates only the full input string with a substring blacklist and first-keyword allowlist, but then… | |
| Analizada | Crítica (9.8) | 0.69% | — | Proxysql | 19/6/2026 | 10/8/2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that… | |
| Analizada | Crítica (10) | 0.23% | — | Proxysql | 19/6/2026 | 10/8/2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is… | |
| Analizada | Alta (8.7) | 0.48% | — | Haproxy | 18/6/2026 | 14/7/2026 | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to… | |
| Analizada | Crítica (9) | 0.58% | — | Haproxy | 18/6/2026 | 14/7/2026 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and… | |
| Aplazada | Alta (8.8) | 0.57% | — | TinyproxyAI | 17/6/2026 | 14/7/2026 | Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to… | |
| Aplazada | Crítica (9.3) | 0.68% | — | TinyproxyAI | 17/6/2026 | 14/7/2026 | Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and… | |
| Aplazada | Crítica (9.3) | 0.68% | — | TinyproxyAI | 17/6/2026 | 14/7/2026 | Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend… | |
| Analizada | Alta (7.5) | 1.1% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 17/6/2026 | 20/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Nginx Proxy ManagerAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. |