Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6994

Опубликовано: 25 апр. 2026
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch name: f8f4f1e02fdc64ecd4acf2d903208dd7285ad3a4. It is suggested to install a patch to address this issue.

EPSS

Процентиль: 14%
0.00228
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.3
redhat
3 месяца назад

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch name: f8f4f1e02fdc64ecd4acf2d903208dd7285ad3a4. It is suggested to install a patch to address this issue.

CVSS3: 6.3
debian
3 месяца назад

A weakness has been identified in Envoy up to 1.33.0. Affected is the ...

CVSS3: 6.3
github
3 месяца назад

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch name: f8f4f1e02fdc64ecd4acf2d903208dd7285ad3a4. It is suggested to install a patch to address this issue.

EPSS

Процентиль: 14%
0.00228
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-74