Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53717— Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

Quick assessment

Affected
envoyproxy gateway
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Envoy Gateway 是一个用于将 Envoy Proxy 作为独立应用或基于 Kubernetes 的应用网关进行管理的开源项目。在 1.7.4 和 1.8.1 之前, 会根据租户可控的 中 的值,去拉取 Docker 或 OCI 中的 Wasm 层。 在验证条目名称或声明大小之前,会使用不可信的 tar 头中的 值来分配内存。因此,一个小型的 PAX 或 GNU tar 头可以声明一个数 TB 大小的条目,尽管周围的 仅限制从流中读取的字节数,而且没有注册表白名单来防止被允许的租户选择攻击者控制的、控制器

CVSS 6.5 · Medium EPSS 0.04% · P14
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53717

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Source: CVE Program / CVE List V5
Vulnerability Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
envoyproxy gateway < 1.7.4 -

II. Public POCs for CVE-2026-53717

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53717

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53717 (3)

Vendor Advisories for CVE-2026-53717 (1)

Vendor Pages for CVE-2026-53717 (2)

Same Patch Batch · envoyproxy · 2026-09-14 · 7 CVEs total

CVE-2026-53713 9.1 CRITICAL Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy
CVE-2026-53714 7.4 HIGH Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in Gat
CVE-2026-53716 6.5 MEDIUM Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
CVE-2026-53719 6.5 MEDIUM Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authoriza
CVE-2026-53718 6.4 MEDIUM Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
CVE-2026-53715 5.3 MEDIUM Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

IV. Related Vulnerabilities

V. Comments for CVE-2026-53717

No comments yet


Leave a comment