Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.3) | 66% | — | Envoyproxy Envoy | 28/5/2021 | 17/6/2026 | Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server… | |
| Modificada | Alta (7.5) | 1.8% | — | Envoyproxy Envoy | 20/5/2021 | 17/6/2026 | An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion. | |
| Modificada | Alta (7.5) | 1.7% | — | Envoyproxy Envoy | 20/5/2021 | 17/6/2026 | An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received. | |
| Modificada | Alta (7.5) | 2.0% | — | Envoyproxy Envoy | 20/5/2021 | 17/6/2026 | An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations. | |
| Modificada | Alta (8.2) | 1.7% | — | Envoyproxy Envoy | 11/3/2021 | 17/6/2026 | Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due… | |
| Modificada | Alta (7.5) | 2.4% | — | Envoyproxy Envoy | 15/12/2020 | 17/6/2026 | Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500. | |
| Modificada | Alta (8.8) | 0.99% | — | Envoyproxy Envoy | 15/12/2020 | 17/6/2026 | Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters). | |
| Modificada | Alta (7.5) | 1.1% | — | Envoyproxy Envoy | 1/10/2020 | 17/6/2026 | Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization. | |
| Modificada | Alta (8.3) | 1.3% | — | Envoyproxy Envoy | 1/10/2020 | 17/6/2026 | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header. | |
| Modificada | Crítica (9) | 3.5% | — | Securenvoy Securmail | 7/8/2020 | 17/6/2026 | SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie. | |
| Modificada | Media (5.4) | 0.25% | — | Envoyproxy Envoy | 14/7/2020 | 17/6/2026 | In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of *.example.com, Envoy would incorrectly allow nested.subdomain.example.com, when it should only… | |
| Modificada | Alta (7.5) | 1.5% | — | Envoyproxy Envoy | 1/7/2020 | 17/6/2026 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections. | |
| Modificada | Alta (7.5) | 1.4% | — | Envoyproxy Envoy | 1/7/2020 | 17/6/2026 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs. | |
| Modificada | Alta (7.5) | 1.7% | — | Envoyproxy Envoy | 1/7/2020 | 17/6/2026 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream. | |
| Modificada | Alta (7.5) | 1.4% | — | Envoyproxy Envoy | 1/7/2020 | 17/6/2026 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames. | |
| Modificada | Baja (3.1) | 1.8% | — | Envoyproxy EnvoyIstio | 15/4/2020 | 17/6/2026 | Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind *.example.com. The outcome should instead be… | |
| Modificada | Media (5.3) | 0.61% | — | Envoyproxy Envoy | 4/3/2020 | 17/6/2026 | CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions… | |
| Modificada | Media (5.3) | 1.3% | — | Envoyproxy Envoy | 4/3/2020 | 2/10/2026 | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in… | |
| Modificada | Alta (7.5) | 1.9% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 4/3/2020 | 2/10/2026 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests. | |
| Modificada | Alta (7.5) | 1.9% | — | Envoyproxy EnvoyRedhat Openshift Service MeshDebian Linux | 4/3/2020 | 2/10/2026 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks. | |
| Modificada | Alta (7.5) | 2.1% | — | Envoyproxy Envoy | 13/12/2019 | 17/6/2026 | An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that… | |
| Modificada | Crítica (9.8) | 2.5% | — | Envoyproxy Envoy | 13/12/2019 | 17/6/2026 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers. | |
| Modificada | Crítica (9.8) | 2.5% | — | Envoyproxy Envoy | 13/12/2019 | 17/6/2026 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control… | |
| Modificada | Alta (7.5) | 1.9% | — | Envoyproxy EnvoyIstio | 11/11/2019 | 17/6/2026 | Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used." | |
| Modificada | Alta (7.5) | 65% | — | Envoyproxy Envoy | 9/10/2019 | 17/6/2026 | Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1.11.1 for HTTP/1.x traffic and all versions of Envoy for HTTP/2 traffic had O(n^2) performance… |