{"schema_version":1,"title":"Envoy Proxy vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in Envoy Proxy: 1 in the last 7 days and 1 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-73548, was published on 21 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/envoy-proxy","json_url":"https://junglewise.ai/threats/vendors/envoy-proxy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/envoy-proxy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":8,"all_time":19,"critical":1,"exploited":1,"last_7_days":1,"last_30_days":1,"last_90_days":1,"last_365_days":18},"latest":[{"cve":"CVE-2026-73548","cvss":7.5,"epss":0.0048,"slug":"cve-2026-73548-envoy-is-an-open-source-edge-and-service-proxy-designed-for-cloud","title":"Envoy HTTP upgrade connection poisoning","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:28.397+00:00","url":"https://junglewise.ai/threats/cve-2026-73548-envoy-is-an-open-source-edge-and-service-proxy-designed-for-cloud"},{"cve":"CVE-2026-48090","cvss":5.9,"slug":"cve-2026-48090-envoy-use-after-free-in-http-oauth2-filter","title":"Envoy use-after-free in HTTP OAuth2 filter","severity":"medium","exploited":false,"published_at":"2026-06-26T19:16:41.59+00:00","url":"https://junglewise.ai/threats/cve-2026-48090-envoy-use-after-free-in-http-oauth2-filter"},{"cve":"CVE-2026-47220","cvss":7.5,"slug":"cve-2026-47220-envoy-denial-of-service-via-null-pointer-dereference-in-log","title":"Envoy denial of service via NULL pointer dereference in log formatting","severity":"high","exploited":false,"published_at":"2026-06-26T19:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-47220-envoy-denial-of-service-via-null-pointer-dereference-in-log"},{"cve":"CVE-2026-47205","cvss":5.9,"slug":"cve-2026-47205-envoy-use-after-free-in-ext-authz-filter-during-stream-teardown","title":"Envoy Use-After-Free in ext_authz filter during stream teardown","severity":"medium","exploited":false,"published_at":"2026-06-26T19:16:40.853+00:00","url":"https://junglewise.ai/threats/cve-2026-47205-envoy-use-after-free-in-ext-authz-filter-during-stream-teardown"},{"cve":"CVE-2026-48743","cvss":7.5,"slug":"cve-2026-48743-envoy-http-3-to-http-1-request-smuggling-in-downstream","title":"Envoy HTTP/3 to HTTP/1 request smuggling in downstream translation","severity":"high","exploited":false,"published_at":"2026-06-26T18:17:00.173+00:00","url":"https://junglewise.ai/threats/cve-2026-48743-envoy-http-3-to-http-1-request-smuggling-in-downstream"},{"cve":"CVE-2026-48706","cvss":5.9,"slug":"cve-2026-48706-envoy-heap-buffer-overflow-in-tcpstatsdsink","title":"Envoy heap buffer overflow in TcpStatsdSink","severity":"medium","exploited":false,"published_at":"2026-06-26T18:17:00.027+00:00","url":"https://junglewise.ai/threats/cve-2026-48706-envoy-heap-buffer-overflow-in-tcpstatsdsink"},{"cve":"CVE-2026-48497","cvss":5.9,"slug":"cve-2026-48497-envoy-denial-of-service-in-udp-dns-filter","title":"Envoy denial of service in UDP DNS filter","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:59.897+00:00","url":"https://junglewise.ai/threats/cve-2026-48497-envoy-denial-of-service-in-udp-dns-filter"},{"cve":"CVE-2026-48044","cvss":7.5,"slug":"cve-2026-48044-envoy-zstd-decompressor-memory-exhaustion-denial-of-service","title":"Envoy Zstd decompressor memory exhaustion Denial of Service","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.767+00:00","url":"https://junglewise.ai/threats/cve-2026-48044-envoy-zstd-decompressor-memory-exhaustion-denial-of-service"},{"cve":"CVE-2026-48042","cvss":7.5,"slug":"cve-2026-48042-envoy-stack-overflow-in-json-object-destructor","title":"Envoy stack overflow in JSON object destructor","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.63+00:00","url":"https://junglewise.ai/threats/cve-2026-48042-envoy-stack-overflow-in-json-object-destructor"},{"cve":"CVE-2026-47778","cvss":4.4,"slug":"cve-2026-47778-envoy-improper-certificate-validation-via-nul-byte-truncation-in","title":"Envoy improper certificate validation via NUL byte truncation in DNS SAN","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:59.48+00:00","url":"https://junglewise.ai/threats/cve-2026-47778-envoy-improper-certificate-validation-via-nul-byte-truncation-in"},{"cve":"CVE-2026-47775","cvss":6.8,"slug":"cve-2026-47775-envoy-oauth2-http-filter-padding-oracle-vulnerability","title":"Envoy OAuth2 HTTP filter padding oracle vulnerability","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:59.35+00:00","url":"https://junglewise.ai/threats/cve-2026-47775-envoy-oauth2-http-filter-padding-oracle-vulnerability"},{"cve":"CVE-2026-47692","cvss":4.8,"slug":"cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch","title":"Envoy PROXY Protocol v2 request smuggling via TLV length mismatch","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.22+00:00","url":"https://junglewise.ai/threats/cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch"},{"cve":"CVE-2026-47221","cvss":5.9,"slug":"cve-2026-47221-envoy-null-pointer-dereference-in-router-filter-internal","title":"Envoy null pointer dereference in router filter internal redirects","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:59.087+00:00","url":"https://junglewise.ai/threats/cve-2026-47221-envoy-null-pointer-dereference-in-router-filter-internal"},{"cve":"CVE-2026-47207","cvss":6.5,"slug":"cve-2026-47207-envoy-use-after-free-in-ext-proc-filter-grpc-message-handling","title":"Envoy use-after-free in ext_proc filter gRPC message handling","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:58.957+00:00","url":"https://junglewise.ai/threats/cve-2026-47207-envoy-use-after-free-in-ext-proc-filter-grpc-message-handling"},{"cve":"CVE-2026-47204","cvss":6.5,"slug":"cve-2026-47204-envoy-proxy-null-pointer-dereference-in-grpc-stats-filter","title":"Envoy Proxy null pointer dereference in grpc_stats filter","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:58.673+00:00","url":"https://junglewise.ai/threats/cve-2026-47204-envoy-proxy-null-pointer-dereference-in-grpc-stats-filter"},{"cve":"CVE-2026-47774","cvss":7.5,"epss":0.0056,"slug":"cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification","title":"Envoy Proxy denial of service via HTTP/2 HPACK amplification","severity":"high","exploited":false,"published_at":"2026-06-17T18:18:02.643+00:00","url":"https://junglewise.ai/threats/cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification"},{"cvss":6.5,"slug":"envoy-ai-gateway-mcp-message-smuggling-via-parser-differential-a56e7319","title":"Envoy AI Gateway MCP message smuggling via parser differential","severity":"medium","exploited":false,"published_at":"2026-05-19T16:18:14+00:00","url":"https://junglewise.ai/threats/envoy-ai-gateway-mcp-message-smuggling-via-parser-differential-a56e7319"},{"cve":"CVE-2026-26308","cvss":7.5,"slug":"cve-2026-26308-envoy-rbac-header-validation-bypass-via-multi-value-concatenation","title":"Envoy RBAC header validation bypass via multi-value concatenation","severity":"high","exploited":false,"published_at":"2026-03-10T18:30:42+00:00","url":"https://junglewise.ai/threats/cve-2026-26308-envoy-rbac-header-validation-bypass-via-multi-value-concatenation"},{"cve":"CVE-2023-44487","cvss":7.5,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"HTTP/2 Rapid Reset Attack Vulnerability","severity":"critical","exploited":true,"published_at":"2023-10-10T14:15:10.883+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"}],"vendor":{"hub":true,"name":"Envoy Proxy","slug":"envoy-proxy","homepage":"https://www.envoyproxy.io/","description":"An open source edge and service proxy designed for cloud-native applications.","url":"https://junglewise.ai/threats/vendors/envoy-proxy"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2023-44487","cvss":7.5,"slug":"cve-2023-44487-http-2-rapid-reset-attack-vulnerability","title":"HTTP/2 Rapid Reset Attack Vulnerability","severity":"critical","exploited":true,"published_at":"2023-10-10T14:15:10.883+00:00","url":"https://junglewise.ai/threats/cve-2023-44487-http-2-rapid-reset-attack-vulnerability"},{"cve":"CVE-2026-47774","cvss":7.5,"epss":0.0056,"slug":"cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification","title":"Envoy Proxy denial of service via HTTP/2 HPACK amplification","severity":"high","exploited":false,"published_at":"2026-06-17T18:18:02.643+00:00","url":"https://junglewise.ai/threats/cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification"},{"cve":"CVE-2026-73548","cvss":7.5,"epss":0.0048,"slug":"cve-2026-73548-envoy-is-an-open-source-edge-and-service-proxy-designed-for-cloud","title":"Envoy HTTP upgrade connection poisoning","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:28.397+00:00","url":"https://junglewise.ai/threats/cve-2026-73548-envoy-is-an-open-source-edge-and-service-proxy-designed-for-cloud"},{"cve":"CVE-2026-47220","cvss":7.5,"slug":"cve-2026-47220-envoy-denial-of-service-via-null-pointer-dereference-in-log","title":"Envoy denial of service via NULL pointer dereference in log formatting","severity":"high","exploited":false,"published_at":"2026-06-26T19:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-47220-envoy-denial-of-service-via-null-pointer-dereference-in-log"},{"cve":"CVE-2026-48743","cvss":7.5,"slug":"cve-2026-48743-envoy-http-3-to-http-1-request-smuggling-in-downstream","title":"Envoy HTTP/3 to HTTP/1 request smuggling in downstream translation","severity":"high","exploited":false,"published_at":"2026-06-26T18:17:00.173+00:00","url":"https://junglewise.ai/threats/cve-2026-48743-envoy-http-3-to-http-1-request-smuggling-in-downstream"},{"cve":"CVE-2026-48044","cvss":7.5,"slug":"cve-2026-48044-envoy-zstd-decompressor-memory-exhaustion-denial-of-service","title":"Envoy Zstd decompressor memory exhaustion Denial of Service","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.767+00:00","url":"https://junglewise.ai/threats/cve-2026-48044-envoy-zstd-decompressor-memory-exhaustion-denial-of-service"},{"cve":"CVE-2026-48042","cvss":7.5,"slug":"cve-2026-48042-envoy-stack-overflow-in-json-object-destructor","title":"Envoy stack overflow in JSON object destructor","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.63+00:00","url":"https://junglewise.ai/threats/cve-2026-48042-envoy-stack-overflow-in-json-object-destructor"},{"cve":"CVE-2026-26308","cvss":7.5,"slug":"cve-2026-26308-envoy-rbac-header-validation-bypass-via-multi-value-concatenation","title":"Envoy RBAC header validation bypass via multi-value concatenation","severity":"high","exploited":false,"published_at":"2026-03-10T18:30:42+00:00","url":"https://junglewise.ai/threats/cve-2026-26308-envoy-rbac-header-validation-bypass-via-multi-value-concatenation"},{"cve":"CVE-2026-47692","cvss":4.8,"slug":"cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch","title":"Envoy PROXY Protocol v2 request smuggling via TLV length mismatch","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.22+00:00","url":"https://junglewise.ai/threats/cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch"},{"cve":"CVE-2026-47775","cvss":6.8,"slug":"cve-2026-47775-envoy-oauth2-http-filter-padding-oracle-vulnerability","title":"Envoy OAuth2 HTTP filter padding oracle vulnerability","severity":"medium","exploited":false,"published_at":"2026-06-26T18:16:59.35+00:00","url":"https://junglewise.ai/threats/cve-2026-47775-envoy-oauth2-http-filter-padding-oracle-vulnerability"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Envoy Proxy","slug":"envoy","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/envoy"}]}