CVE-2026-53717Medium· 6.5▾ SunlitEnvoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/envoyproxy/gateway >= 1.8.0-rc.0, < 1.8.1github.com/envoyproxy/gateway < 1.7.4Patched in:
github.com/envoyproxy/gateway 1.8.1github.com/envoyproxy/gateway 1.7.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53716Medium· 6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
CVE-2026-53718Medium· 6.4Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
CVE-2026-53719Medium· 6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
CVE-2026-53715Medium· 5.3Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
CVE-2026-53713Critical· 9.1Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
CVE-2026-53714High· 7.4Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway