Envoy Gateway 是一个开源项目,用于将 Envoy Proxy 作为独立应用程序网关或基于 Kubernetes 的应用程序网关进行管理。 在 1.7.4 和 1.8.1 之前,位于 中的 函数在处理安全策略时会引用一个为空的授权值:当某个命名空间范围内的租户创建了一个针对 TCPRoute 的 SecurityPolicy,并且在 中省略了授权配置时,就会触发该问题。 这个持久化对象会在每次协调(reconcile)时触发 panic(空指针解引用); 中的恢复机制虽然能让进程保持运行,但会导致 中的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| envoyproxy | gateway | < 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53713 | 9.1 CRITICAL | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy |
| CVE-2026-53714 | 7.4 HIGH | Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in Gat |
| CVE-2026-53716 | 6.5 MEDIUM | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit |
| CVE-2026-53717 | 6.5 MEDIUM | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar head |
| CVE-2026-53718 | 6.4 MEDIUM | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass |
| CVE-2026-53715 | 5.3 MEDIUM | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock |
No comments yet