Junglewise Threat Intelligence

CVE-2026-53713: Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and

CVE-2026-53713 · Severity: critical · CVSS 9.1 · Published 2026-09-14

Technologies: github.com/envoyproxy/gateway (Go). Vendors: Go, Envoy Proxy.

Executive brief

Envoy Gateway is a tool used to manage network traffic and security policies for applications. A vulnerability in its Lua extension policy allows an attacker with basic permissions to bypass security checks and read sensitive files from the system. This could lead to the theft of Kubernetes service tokens, TLS certificates, and other credentials, potentially allowing an attacker to gain broader control over the cloud environment.

Technical details

An authentication bypass exists in Envoy Gateway's EnvoyExtensionPolicy due to improper input validation in the Lua 'to_absolute_normalized_path' function. The function fails to collapse redundant path separators (e.g., '//'), which allows attackers to bypass 'is_critical_path' checks that only look for single-slash prefixes like '/etc/'. By submitting malicious Lua code via an EnvoyExtensionPolicy, a remote attacker with low privileges can perform an arbitrary file read on the gateway controller pod's filesystem. This can be used to disclose Kubernetes SA tokens, TLS certificates, and process environment variables. The issue is fixed in versions 1.7.4 and 1.8.1 by ensuring path normalization collapses separators and rejecting directory traversal segments.

Affected products

  • envoyproxy gateway < 1.7.4, >= 1.8.0-rc.0, < 1.8.1

Timeline

  • 2026-06-05: disclosed
  • 2026-07-16: advisory: GitHub Advisory published

References

Related threats