VulnSea

envoyproxy has 10 CVEs on record between 2019 and 2026. Disclosure cadence is accelerating: 7 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: gateway (8), envoy (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
7 prev 1

Products

  • gateway 8
  • envoy 2
10
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

envoyproxy vulnerabilities

CVEs affecting envoyproxy, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-53718Medium· 6.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…

Sunlitenvoyproxy · gatewayEPSS 0.33%via NVD
CVE-2026-53716Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…

Sunlitenvoyproxy · gatewayEPSS 0.69%via NVD
CVE-2026-53719Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a n…

Sunlitenvoyproxy · gatewayEPSS 0.69%via NVD
CVE-2026-53717Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…

Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53715Medium· 5.3
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

Sunlitenvoyproxy · gatewayEPSS 0.36%via NVD
CVE-2026-53713Critical· 9.1
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

Midnightenvoyproxy · gatewayEPSS 0.41%via NVD
CVE-2026-53714High· 7.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

Twilightenvoyproxy · gatewayEPSS 0.28%via NVD
CVE-2026-47774High· 7.5
3mo ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remot…

Twilightenvoyproxy · envoyEPSS 0.97%via NVD
CVE-2026-22771High· 8.8
8mo ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's …

Twilightenvoyproxy · gatewayEPSS 0.63%via NVD
CVE-2019-9901Medium· 6.5
7y ago

Envoy 1.9.0 and before does not normalize HTTP URL paths

Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server could then interpret the non-normalized …

Sunlitenvoyproxy · envoyEPSS 4.6%via NVD
envoyproxy vulnerabilities (CVEs) · VulnSea