
CVE-2026-6994 A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc … https://www.cve.org/CVERecord?id=CVE-2026-6994
Post summary
A weakness in Envoy up to version 1.33.0 affecting the header_mutation filter's `params.add` function (CVE‑2026‑6994) has been announced; no PoC, exploit, patch, or active exploitation details are provided.

