Is Envoy 1.11.2 patched?
Current stable (1.38.2): 100/100
1.11.2 has 30 open critical-or-high vulnerabilities. Run 1.34.13 or later to clear them. See what 1.34.13 fixes →
Summary iPlain-English security status for Envoy 1.11.2, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Envoy 1.11.2 is part of the 1.11 release line. 60 known vulnerabilities affect it. The minimum safe version is 1.34.13 — upgrade to it or later to clear the open critical/high issues. The 1.11 line reached end-of-life on 2019-10-31, so it no longer receives security patches. The latest supported Envoy release is 1.38.2.
Known issues affecting 1.11.2
Exploited first, then by exploitation probability.
CVE-2024-30255 MEDIUM EPSS 88% → fixed in 1.29.3 CVE-2021-29492 HIGH EPSS 68% → fixed in 1.18.3 CVE-2019-15226 HIGH EPSS 65% → see advisory CVE-2019-18801 CRITICAL EPSS 3% → see advisory CVE-2019-18802 CRITICAL EPSS 2% → see advisory CVE-2020-35471 HIGH EPSS 2% → fixed in 1.16.1 CVE-2019-18838 HIGH EPSS 2% → see advisory CVE-2020-11767 LOW EPSS 2% → see advisory CVE-2020-12604 HIGH EPSS 2% → see advisory CVE-2021-39204 HIGH EPSS 2% → fixed in 1.18.4 CVE-2021-39162 HIGH EPSS 2% → fixed in 1.18.4 CVE-2020-8663 HIGH EPSS 1% → see advisory CVE-2020-12603 HIGH EPSS 1% → see advisory CVE-2020-12605 HIGH EPSS 1% → see advisory CVE-2022-29225 HIGH EPSS 1% → fixed in 1.22.1 CVE-2021-39206 HIGH EPSS 1% → fixed in 1.18.4 CVE-2020-25017 HIGH EPSS 1% → fixed in 1.15.1 CVE-2022-29226 CRITICAL EPSS 1% → fixed in 1.22.1 CVE-2022-29228 HIGH EPSS 1% → fixed in 1.22.1 CVE-2022-29227 HIGH EPSS 1% → fixed in 1.22.1Other Envoy versions
Check another release line of Envoy.
Frequently asked
Is Envoy 1.11.2 patched?
Envoy 1.11.2 is end-of-life and no longer receives security patches. Move to 1.38.2.
What version should I upgrade Envoy 1.11.2 to?
Upgrade Envoy 1.11.2 to at least 1.34.13 to clear its 30 open critical-or-high vulnerabilities.
When does Envoy 1.11 reach end-of-life?
Envoy 1.11 reached end-of-life on 2019-10-31 and no longer receives security patches.
What is the latest version of Envoy?
The latest supported Envoy release is 1.38.2.
Is Envoy 1.11.2 still receiving security updates?
No — Envoy 1.11.2 is on the 1.11 line, which reached end-of-life on 2019-10-31 and no longer receives security updates. Upgrade to 1.38.2 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Envoy Proxy's official advisory before you patch or upgrade — Envoy official site ↗