By vendor

Envoyproxy vulnerabilities

Known CVEs affecting Envoyproxy products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-47774HIGH 7.5

    Envoy, a widely-deployed HTTP/2 proxy for cloud applications, contains a memory exhaustion vulnerability that allows attackers to crash the service without authentication. The flaw stems from inadequate header size validation: cookie headers bypass size checks, and compressed header blocks can decompress to enormous sizes that aren't capped. An attacker can exploit this combination to force Envoy to allocate excessive memory, triggering out-of-memory errors and service downtime. Affected versions are older than 1.35.11, 1.36.7, 1.37.3, and 1.38.1.