CVE security advisories and vulnerability history for envoy by envoyproxy.
98
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
24
Public exploits
With known exploit
6.8
Avg CVSS
2019–2026
Last updated
Overview
envoyproxy envoy has 98 published CVE records since 2019, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 24 have a known public exploit. The average CVSS base score across scored CVEs is 6.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting envoyproxy envoy, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of envoyproxy envoy's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High36
Medium38
Low1
22 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of envoyproxy envoy's CVEs is confirmed exploited in the wild.
Public exploits
24
24 of envoyproxy envoy's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every envoyproxy envoy version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about envoyproxy envoy vulnerabilities.
How many CVEs does envoyproxy envoy have?
envoyproxy envoy has 98 published CVE records since 2019.
How many envoyproxy envoy CVEs are in CISA KEV?
Yes — 1 of envoyproxy envoy's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for envoyproxy envoy vulnerabilities?
Yes — 24 of envoyproxy envoy's CVEs have a known public exploit.
Which versions of envoyproxy envoy are affected?
516 distinct envoyproxy envoy versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in envoyproxy envoy CVEs?
envoyproxy envoy's CVEs most often map to these CWE weakness types: CWE-416 (Use After Free), CWE-20 (Improper Input Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-670 (Always-Incorrect Control Flow Implementation).
How many critical envoyproxy envoy vulnerabilities are there?
envoyproxy envoy has 1 critical and 36 high-severity CVEs.
What is the average severity of envoyproxy envoy CVEs?
The average CVSS base score across envoyproxy envoy's scored CVEs is 6.8.