CVE-2026-53714
- EPSS -
- Veröffentlicht 14.09.2026 20:17:22
- Zuletzt bearbeitet 30.09.2026 17:43:24
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deploy.type=Gatewa...
CVE-2026-53716
- EPSS -
- Veröffentlicht 14.09.2026 20:15:51
- Zuletzt bearbeitet 30.09.2026 17:43:24
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decom...
CVE-2026-53715
- EPSS -
- Veröffentlicht 14.09.2026 20:14:34
- Zuletzt bearbeitet 25.09.2026 14:10:13
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without sync...
CVE-2026-53719
- EPSS -
- Veröffentlicht 14.09.2026 20:13:20
- Zuletzt bearbeitet 30.09.2026 17:43:24
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorizat...
CVE-2026-53718
- EPSS -
- Veröffentlicht 14.09.2026 20:12:12
- Zuletzt bearbeitet 25.09.2026 14:10:13
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another...
CVE-2026-53713
- EPSS -
- Veröffentlicht 14.09.2026 20:11:02
- Zuletzt bearbeitet 30.09.2026 17:43:24
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redunda...
CVE-2026-53717
- EPSS -
- Veröffentlicht 14.09.2026 20:09:44
- Zuletzt bearbeitet 30.09.2026 17:43:24
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.ur...
CVE-2026-22771
- EPSS 0.58%
- Veröffentlicht 12.01.2026 18:08:22
- Zuletzt bearbeitet 15.07.2026 02:18:35
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. ...
CVE-2025-25294
- EPSS 0.28%
- Veröffentlicht 06.03.2025 19:15:27
- Zuletzt bearbeitet 04.09.2025 13:52:34
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This format is vu...
CVE-2025-24030
- EPSS 0.42%
- Veröffentlicht 23.01.2025 04:15:07
- Zuletzt bearbeitet 04.09.2025 14:02:18
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxie...