6.5
CVE-2026-53716
- EPSS -
- Veröffentlicht 14.09.2026 20:15:51
- Zuletzt bearbeitet 30.09.2026 17:43:24
- Erkennungen
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload. The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller. The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerenvoyproxy
≫
Produkt
gateway
Version
< 1.7.4
Status
affected
Version
>= 1.8.0-rc.0, < 1.8.1
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://github.com/envoyproxy/gateway/pull/9171
https://github.com/envoyproxy/gateway/pull/9172
https://github.com/envoyproxy/gateway/pull/9173
https://github.com/envoyproxy/gateway/commit/5a78db82b7cf4fc5bebbeda2c50952892038a464
https://github.com/envoyproxy/gateway/commit/96e2b750868a459ace4b8b68e6a6e4fb0152b9b7
https://github.com/envoyproxy/gateway/commit/b4737180c7e597490c6363075c565fa8cf24eead
https://github.com/envoyproxy/gateway/releases/tag/v1.7.4
https://github.com/envoyproxy/gateway/releases/tag/v1.8.1
https://github.com/envoyproxy/gateway/security/advisories/GHSA-cxpq-8v7q-cg56