93 exploited vulnerabilities in Envoy
- Vendors
- Cloudflare, Lyft, Nginx, Ory, Astra Linux, Cilium
- With known exploits
- 93
- Affected Linux Linux Kernel versions
- < 5.4.292, 5.10.236, 5.15.180, 6.1.133, 6.6.86, 6.12.22, 6.13.10, 6.14
- Affected Envoyproxy Envoy versions
- β€ 1.12.1, 1.26.7, 1.27.3, 1.28.1, 1.29.1, 1.29.0, 1.23.11, 1.24.9, 1.25.8, 1.26.3, 1.35.13, 1.36.9, 1.37.5, 1.38.3
- Affected Cilium versions
- < 1.17.14, 1.18.8, 1.19.2
- Affected Apache Http Server versions
- < 2.4.68
- Affected Debian Debian Linux versions
- = 11.0
Vulnerabilities with exploits
Highest CVSS first β 2 of these already have exploit code on Sploitus
CVE-2026-33494
CVE-2025-22021
CVE-2022-29226
CVE-2022-29225
CVE-2019-9901
CVE-2019-18802
CVE-2019-18801
CVE-2023-27493
CVE-2026-49445
CVE-2024-39305
CVE-2023-35941
CVE-2025-55162
CVE-2026-26061
CVE-2024-23324
CVE-2024-53271
CVE-2023-35944
CVE-2023-27487
CVE-2020-25017
CVE-2019-9900
CVE-2026-26308
CVE-2026-41246
CVE-2024-53270
CVE-2024-32475
CVE-2024-23323
CVE-2024-23327
CVE-2024-23325
CVE-2024-23322
CVE-2024-27919 1 exploit
CVE-2023-35945
CVE-2019-18836
CVE-2026-47220
CVE-2026-48706
CVE-2026-48497
CVE-2026-48044
CVE-2026-48042
CVE-2026-47221
CVE-2026-47204
CVE-2026-48743
CVE-2026-47774
CVE-2026-49975 7 exploits
Exploit for Memory Allocation with Excessive Size Value in Apache Http_ServerExploit for Memory Allocation with Excessive Size Value in Apache Http_Server
CVE-2026-26330
CVE-2026-26310
CVE-2025-62504
CVE-2025-62409
CVE-2025-54588
CVE-2025-30157
CVE-2024-45810
CVE-2024-45809
CVE-2024-45807
CVE-2024-34363