Junglewise Threat Intelligence

CVE-2026-53717: Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and

CVE-2026-53717 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: github.com/envoyproxy/gateway (Go). Vendors: Go, Envoy Proxy.

Executive brief

Envoy Gateway is a tool used to manage network traffic and security policies in cloud environments. A vulnerability in how it handles container image layers allows an attacker to crash the management controller by providing a specially crafted image. This results in a persistent denial-of-service, preventing administrators from managing their network traffic until the system is patched.

Technical details

A memory allocation vulnerability (CWE-789) exists in Envoy Gateway's image fetching logic within `imagefetcher.go`. The component uses the `h.Size` value from a TAR header to allocate a byte slice without verifying if the size is within reasonable limits. An attacker with permissions to create an `EnvoyExtensionPolicy` can point the controller to a malicious OCI registry containing a TAR layer with a manipulated header (e.g., using PAX/GNU encoding to claim a multi-terabyte size). This triggers an unrecoverable Out-of-Memory (OOM) error in the Go runtime, causing the shared controller to crash-loop. Patches are available in versions 1.8.1 and 1.7.4.

Affected products

  • Envoy Proxy Gateway >= 1.8.0-rc.0, < 1.8.1; < 1.7.4

Timeline

  • 2026-06-05: disclosed
  • 2026-07-16: advisory

References

Related threats