Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

166 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.3)66%—Envoyproxy Envoy28/5/202117/6/2026
Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server…
ModificadaAlta (7.5)1.8%—Envoyproxy Envoy20/5/202117/6/2026
An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.
ModificadaAlta (7.5)1.7%—Envoyproxy Envoy20/5/202117/6/2026
An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.
ModificadaAlta (7.5)2.0%—Envoyproxy Envoy20/5/202117/6/2026
An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.
ModificadaAlta (8.2)1.7%—Envoyproxy Envoy11/3/202117/6/2026
Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the `allow_missing` requirement under `requires_any` due…
ModificadaAlta (7.5)2.4%—Envoyproxy Envoy15/12/202017/6/2026
Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.
ModificadaAlta (8.8)0.99%—Envoyproxy Envoy15/12/202017/6/2026
Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).
ModificadaAlta (7.5)1.1%—Envoyproxy Envoy1/10/202017/6/2026
Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
ModificadaAlta (8.3)1.3%—Envoyproxy Envoy1/10/202017/6/2026
Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.
ModificadaCrítica (9)3.5%—Securenvoy Securmail7/8/202017/6/2026
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.
ModificadaMedia (5.4)0.25%—Envoyproxy Envoy14/7/202017/6/2026
In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of *.example.com, Envoy would incorrectly allow nested.subdomain.example.com, when it should only…
ModificadaAlta (7.5)1.5%—Envoyproxy Envoy1/7/202017/6/2026
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections.
ModificadaAlta (7.5)1.4%—Envoyproxy Envoy1/7/202017/6/2026
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when processing HTTP/1.1 headers with long field names or requests with long URLs.
ModificadaAlta (7.5)1.7%—Envoyproxy Envoy1/7/202017/6/2026
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset the stream.
ModificadaAlta (7.5)1.4%—Envoyproxy Envoy1/7/202017/6/2026
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may consume excessive amounts of memory when proxying HTTP/2 requests or responses with many small (i.e. 1 byte) data frames.
ModificadaBaja (3.1)1.8%—Envoyproxy EnvoyIstio15/4/202017/6/2026
Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured explicitly (e.g., abc.example.com) is sent to the server(s) listening behind *.example.com. The outcome should instead be…
ModificadaMedia (5.3)0.61%—Envoyproxy Envoy4/3/202017/6/2026
CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have been matched to a wrong filter chain, possibly bypassing some security restrictions…
ModificadaMedia (5.3)1.3%—Envoyproxy Envoy4/3/20202/10/2026
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in…
ModificadaAlta (7.5)1.9%—Envoyproxy EnvoyRedhat Openshift Service Mesh4/3/20202/10/2026
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
ModificadaAlta (7.5)1.9%—Envoyproxy EnvoyRedhat Openshift Service MeshDebian Linux4/3/20202/10/2026
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
ModificadaAlta (7.5)2.1%—Envoyproxy Envoy13/12/201917/6/2026
An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that…
ModificadaCrítica (9.8)2.5%—Envoyproxy Envoy13/12/201917/6/2026
An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.
ModificadaCrítica (9.8)2.5%—Envoyproxy Envoy13/12/201917/6/2026
An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control…
ModificadaAlta (7.5)1.9%—Envoyproxy EnvoyIstio11/11/201917/6/2026
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."
ModificadaAlta (7.5)65%—Envoyproxy Envoy9/10/201917/6/2026
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1.11.1 for HTTP/1.x traffic and all versions of Envoy for HTTP/2 traffic had O(n^2) performance…
Orbitaley — Vulnerabilidades