CVE-2020-8664Medium· 5.3▾ SunlitCNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined validation context could lead to the “static” part of the validation context to be not applied, even though it was visible in the active config dump.
envoy <= 1.13.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-8661High· 7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CVE-2020-8659High· 7.5CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e
CVE-2025-66220Medium· 5.0Envoy is a high-performance edge/middle/service proxy
CVE-2025-64527Medium· 6.5Envoy is a high-performance edge/middle/service proxy
CVE-2026-73551Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-73553High· 7.5Envoy is an open source edge and service proxy designed for cloud-native applications