CVE-2020-25018: Envoyproxy Envoy

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

Affected products

  • Envoyproxy Envoy: from 2d69e30, before 3b5acb2 (fixed in 3b5acb2)

Published 2020-10-01. Last modified 2026-06-17.