Envoyproxy / Gateway
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-53714 | Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode | HIGH | 7.4 | Sep 14, 2026 |
| CVE-2026-53716 | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit | MEDIUM | 6.5 | Sep 14, 2026 |
| CVE-2026-53715 | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock | MEDIUM | 5.3 | Sep 14, 2026 |
| CVE-2026-53719 | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization | MEDIUM | 6.5 | Sep 14, 2026 |
| CVE-2026-53718 | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass | MEDIUM | 6.4 | Sep 14, 2026 |
| CVE-2026-53713 | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure | CRITICAL | 9.1 | Sep 14, 2026 |
| CVE-2026-53717 | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header | MEDIUM | 6.5 | Sep 14, 2026 |
| CVE-2026-22771 | Envoy Extension Policy lua scripts injection causes arbitrary command execution | HIGH | 8.8 | Jan 12, 2026 |
| CVE-2025-25294 | Envoy Gateway Log Injection Vulnerability | MEDIUM | 5.3 | Mar 6, 2025 |
| CVE-2025-24030 | Envoy Admin Interface Exposed through prometheus metrics endpoint | HIGH | 7.1 | Jan 23, 2025 |
Showing 1 to 10 of 10 CVEs