Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Gateway — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Gateway, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Gateway product, specifically focusing on network access control weaknesses. It collects advisories related to unauthorized access, authentication bypass, and input validation flaws affecting the Gateway component. The data spans the full historical record available in the database, covering all published security bulletins. Readers can track the vendor's advisory timeline, understand the specific class of weaknesses impacting this product, and review the complete vulnerability history for Gateway. No specific CVE identifiers are listed, allowing users to focus on patterns and trends rather than individual ticket numbers.

Vendor: Devolutions

CVE ID Title CVSS Severity Published
CVE-2026-53714 Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode CWE-306 7.4 High 2026-09-14
CVE-2026-53716 Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit CWE-789 6.5 Medium 2026-09-14
CVE-2026-53715 Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock CWE-362 5.3 Medium 2026-09-14
CVE-2026-53719 Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization CWE-476 6.5 Medium 2026-09-14
CVE-2026-53718 Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass CWE-862 6.4 Medium 2026-09-14
CVE-2026-53713 Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure CWE-20 9.1 Critical 2026-09-14
CVE-2026-53717 Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header CWE-789 6.5 Medium 2026-09-14
CVE-2026-82270 Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* CWE-918 7.5 High 2026-08-28
CVE-2026-22771 Envoy Extension Policy lua scripts injection causes arbitrary command execution CWE-94 8.8 High 2026-01-12
CVE-2025-66405 Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host CWE-918 6.5AI Medium AI 2025-12-01
CVE-2025-25294 Envoy Gateway Log Injection Vulnerability CWE-117 5.3 Medium 2025-03-06
CVE-2025-24030 Envoy Admin Interface Exposed through prometheus metrics endpoint CWE-419 7.1 High 2025-01-23
CVE-2024-52528 Auth Token can be passed dummy or wrong the middleware response is 200 OK CWE-285 9.8AI Critical AI 2024-11-15
CVE-2023-1580 Devolutions Gateway 资源管理错误漏洞 7.5 - 2023-03-22

All 14 known CVE vulnerabilities affecting Gateway with full Chinese analysis, references, and POCs where available.