Envoy Gateway 是一个开源项目,用于将 Envoy Proxy 作为独立应用程序网关或基于 Kubernetes 的应用程序网关进行管理。在 1.7.4 和 1.8.1 版本之前, 中的 函数在 评估通过 提交的 Lua 代码之前,未能消除冗余的路径分隔符(例如双斜杠 )。在 Linux 系统中,带有双斜杠的绝对路径会被解析为对应的单斜杠路径,但该验证器未能匹配这种包含冗余分隔符的路径形式,从而使得提交的 Lua 代码能够读取网关控制器 Pod 中的任意文件。 被暴露的文件可能包括 Kubernetes
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | gateway | < 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53714 | 7.4 HIGH | Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in Gat |
| CVE-2026-53716 | 6.5 MEDIUM | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit |
| CVE-2026-53719 | 6.5 MEDIUM | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authoriza |
| CVE-2026-53717 | 6.5 MEDIUM | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar head |
| CVE-2026-53718 | 6.4 MEDIUM | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass |
| CVE-2026-53715 | 5.3 MEDIUM | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock |
No comments yet