Junglewise Threat Intelligence

CVE-2026-53715: Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and

CVE-2026-53715 · Severity: medium · CVSS 5.3 · Published 2026-09-14

Technologies: github.com/envoyproxy/gateway (Go). Vendors: Envoy Proxy, Go.

Executive brief

Envoy Gateway is a tool used to manage network traffic and security policies for applications. A flaw in how it handles internal data for WebAssembly (Wasm) modules can allow an attacker to crash the gateway's control system. This results in a service outage (Denial of Service), though the system is typically configured to restart automatically.

Technical details

A race condition exists in `httpserver.go` within the Envoy Gateway Wasm cache component. The `ServeHTTP` function performs an un-synchronized read of the `mappingPath2Cache` map at line 153, while concurrent writes occur under a lock at lines 201/209. Because Go's runtime throws an unrecoverable error when it detects concurrent map read/writes, the controller process terminates. An attacker with the ability to create `EnvoyExtensionPolicy` objects can trigger this by rapidly updating Wasm URLs while simultaneously flooding the HTTP server on port 18002. The vulnerability is patched in versions 1.7.4 and 1.8.1.

Affected products

  • Envoy Proxy gateway >= 1.8.0-rc.0, < 1.8.1; < 1.7.4

Timeline

  • 2026-06-05: disclosed: Initial disclosure by zirain
  • 2026-07-16: advisory: GitHub Advisory published

References

Related threats