gateway vulnerabilities
CVEs whose affected-version data names the gateway package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
CVE-2026-53718Medium· 6.4Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…
CVE-2026-53716Medium· 6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…
CVE-2026-53719Medium· 6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a n…
CVE-2026-53717Medium· 6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…
CVE-2026-53715Medium· 5.3Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…
CVE-2026-53713Critical· 9.1Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…
CVE-2026-53714High· 7.4Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…
CVE-2026-22771High· 8.8Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's …