Executive brief
Envoy Gateway is a tool used to manage network traffic and security policies for applications. A flaw in how it handles internal data for WebAssembly (Wasm) modules can allow an attacker to crash the gateway's control system. This results in a service outage (Denial of Service), though the system is typically configured to restart automatically.
Technical details
A race condition exists in `httpserver.go` within the Envoy Gateway Wasm cache component. The `ServeHTTP` function performs an un-synchronized read of the `mappingPath2Cache` map at line 153, while concurrent writes occur under a lock at lines 201/209. Because Go's runtime throws an unrecoverable error when it detects concurrent map read/writes, the controller process terminates. An attacker with the ability to create `EnvoyExtensionPolicy` objects can trigger this by rapidly updating Wasm URLs while simultaneously flooding the HTTP server on port 18002. The vulnerability is patched in versions 1.7.4 and 1.8.1.
Affected products
- Envoy Proxy gateway >= 1.8.0-rc.0, < 1.8.1; < 1.7.4
Timeline
- 2026-06-05: disclosed: Initial disclosure by zirain
- 2026-07-16: advisory: GitHub Advisory published