Envoy Gateway 是一个用于管理 Envoy Proxy 作为独立应用或基于 Kubernetes 的应用网关的开源项目。在 1.7.4 和 1.8.1 版本之前, 中的 在读取未加同步保护的普通映射 时, 在 EnvoyExtensionPolicy 转换过程中写入同一个 map。一个拥有 pod 网络访问权限(针对未认证端口 18002)且具有租户权限以频繁创建/销毁使用不同 Wasm URL 的策略的攻击者,可以通过发送大量 GET 请求,使某个请求的读取操作与写入操作发生重叠。Go 语言对并发 m
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | gateway | < 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53713 | 9.1 CRITICAL | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy |
| CVE-2026-53714 | 7.4 HIGH | Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in Gat |
| CVE-2026-53716 | 6.5 MEDIUM | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit |
| CVE-2026-53719 | 6.5 MEDIUM | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authoriza |
| CVE-2026-53717 | 6.5 MEDIUM | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar head |
| CVE-2026-53718 | 6.4 MEDIUM | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass |
No comments yet