Ryan Northey
9 exploits
Active since Feb 2024
Envoy Query Parameter header_mutation.cc params.add injection
CVSS 6.3
Envoy <1.37.1/1.36.5/1.35.8/1.34.13 - Auth Bypass
CVSS 7.5
Envoy 1.26.0-1.26.6 - Use-After-Free in Timeout Handling
CVSS 7.5
Envoy 1.26.0-1.26.6 - Inefficient CPU Computation via Regex Matcher
CVSS 4.3
Envoy 1.26.0-1.26.6 - Authentication Bypass via Invalid gRPC Request
CVSS 8.6
Envoy 1.26.0-1.26.6 - Denial of Service via Proxy Protocol IPv6 Address Handling
CVSS 7.5
Envoy 1.26.0-1.26.6 - Denial of Service via PPv2 Header Crafting
CVSS 7.5
Envoy 1.31.0-1.31.4 - Denial of Service via HTTP 1.1 Non-101 1xx Response Handling
CVSS 7.1
Envoy < 1.33.1, 1.32.4, 1.31.6, 1.30.10 - Denial of Service via ext_proc HTTP Filter Local Reply
CVSS 6.5