Envoy Gateway 是一个用于将 Envoy Proxy 作为独立应用或基于 Kubernetes 的应用网关进行管理的开源项目。在 1.7.4 和 1.8.1 之前的版本中,当通过 配置 GatewayNamespaceMode 时,xDS gRPC 服务器安装了 JWT 流式拦截器(StreamInterceptor),但未安装一元拦截器(UnaryInterceptor),导致所有一元 Fetch RPC 请求均未经过身份验证。此外,流式拦截器仅对 消息进行身份验证;而在 State-of-the-W
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | gateway | < 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53713 | 9.1 CRITICAL | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy |
| CVE-2026-53716 | 6.5 MEDIUM | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit |
| CVE-2026-53719 | 6.5 MEDIUM | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authoriza |
| CVE-2026-53717 | 6.5 MEDIUM | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar head |
| CVE-2026-53718 | 6.4 MEDIUM | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass |
| CVE-2026-53715 | 5.3 MEDIUM | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock |
No comments yet