Executive brief
Envoy Gateway is a tool used to manage network traffic and security policies in cloud environments. A vulnerability in how it handles container image layers allows an attacker to crash the management controller by providing a specially crafted image. This results in a persistent denial-of-service, preventing administrators from managing their network traffic until the system is patched.
Technical details
A memory allocation vulnerability (CWE-789) exists in Envoy Gateway's image fetching logic within `imagefetcher.go`. The component uses the `h.Size` value from a TAR header to allocate a byte slice without verifying if the size is within reasonable limits. An attacker with permissions to create an `EnvoyExtensionPolicy` can point the controller to a malicious OCI registry containing a TAR layer with a manipulated header (e.g., using PAX/GNU encoding to claim a multi-terabyte size). This triggers an unrecoverable Out-of-Memory (OOM) error in the Go runtime, causing the shared controller to crash-loop. Patches are available in versions 1.8.1 and 1.7.4.
Affected products
- Envoy Proxy Gateway >= 1.8.0-rc.0, < 1.8.1; < 1.7.4
Timeline
- 2026-06-05: disclosed
- 2026-07-16: advisory