CVE-2026-53717
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/envoyproxy/gatewayGo | >= 1.8.0-rc.0, < 1.8.1 | 1.8.1 |
github.com/envoyproxy/gatewayGo | < 1.7.4 | 1.7.4 |
Affected products
36- Range: <1.7.4, <1.8.1
- osv-coords35 versionspkg:apk/chainguard/datadog-cluster-agent-7.73pkg:apk/chainguard/datadog-cluster-agent-7.74pkg:apk/chainguard/datadog-cluster-agent-7.76pkg:apk/chainguard/datadog-cluster-agent-7.77pkg:apk/chainguard/datadog-cluster-agent-7.78pkg:apk/chainguard/datadog-cluster-agent-7.79pkg:apk/chainguard/datadog-cluster-agent-7.80pkg:apk/chainguard/datadog-cluster-agent-fips-7.73pkg:apk/chainguard/datadog-cluster-agent-fips-7.74pkg:apk/chainguard/datadog-cluster-agent-fips-7.76pkg:apk/chainguard/datadog-cluster-agent-fips-7.77pkg:apk/chainguard/datadog-cluster-agent-fips-7.78pkg:apk/chainguard/datadog-cluster-agent-fips-7.79pkg:apk/chainguard/datadog-cluster-agent-fips-7.80pkg:apk/chainguard/gitlab-operatorpkg:apk/chainguard/gitlab-operator-fipspkg:apk/chainguard/tigera-operator-1.38pkg:apk/chainguard/tigera-operator-1.40pkg:apk/chainguard/tigera-operator-1.41pkg:apk/chainguard/tigera-operator-1.42pkg:apk/chainguard/tigera-operator-fips-1.38pkg:apk/chainguard/tigera-operator-fips-1.40pkg:apk/chainguard/tigera-operator-fips-1.41pkg:apk/chainguard/tigera-operator-fips-1.42pkg:apk/wolfi/datadog-cluster-agent-7.73pkg:apk/wolfi/datadog-cluster-agent-7.74pkg:apk/wolfi/datadog-cluster-agent-7.76pkg:apk/wolfi/datadog-cluster-agent-7.77pkg:apk/wolfi/datadog-cluster-agent-7.78pkg:apk/wolfi/datadog-cluster-agent-7.79pkg:apk/wolfi/datadog-cluster-agent-7.80pkg:apk/wolfi/tigera-operator-1.40pkg:apk/wolfi/tigera-operator-1.41pkg:apk/wolfi/tigera-operator-1.42pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 7.73.3-r23+ 34 more
- (no CPE)range: < 7.73.3-r23
- (no CPE)range: < 7.74.1-r24
- (no CPE)range: < 7.76.3-r32
- (no CPE)range: < 7.77.3-r23
- (no CPE)range: < 7.78.4-r16
- (no CPE)range: < 7.79.2-r15
- (no CPE)range: < 7.80.4-r7
- (no CPE)range: < 7.73.3-r26
- (no CPE)range: < 7.74.1-r26
- (no CPE)range: < 7.76.3-r32
- (no CPE)range: < 7.77.3-r29
- (no CPE)range: < 7.78.4-r14
- (no CPE)range: < 7.79.2-r8
- (no CPE)range: < 7.80.4-r5
- (no CPE)range: < 3.1.2-r1
- (no CPE)range: < 3.2.0-r0
- (no CPE)range: < 0
- (no CPE)range: < 1.40.13-r4
- (no CPE)range: < 0
- (no CPE)range: < 1.42.4-r2
- (no CPE)range: < 0
- (no CPE)range: < 1.40.13-r5
- (no CPE)range: < 0
- (no CPE)range: < 1.42.4-r4
- (no CPE)range: < 7.73.3-r23
- (no CPE)range: < 7.74.1-r24
- (no CPE)range: < 7.76.3-r32
- (no CPE)range: < 7.77.3-r23
- (no CPE)range: < 7.78.4-r16
- (no CPE)range: < 7.79.2-r15
- (no CPE)range: < 7.80.4-r7
- (no CPE)range: < 1.40.13-r4
- (no CPE)range: < 0
- (no CPE)range: < 1.42.4-r2
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-h7pq-86h8-rp5xghsaADVISORY
- github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5xnvdWEB
- github.com/envoyproxy/gateway/commit/5a78db82b7cf4fc5bebbeda2c50952892038a464nvd
- github.com/envoyproxy/gateway/commit/96e2b750868a459ace4b8b68e6a6e4fb0152b9b7nvd
- github.com/envoyproxy/gateway/commit/b4737180c7e597490c6363075c565fa8cf24eeadnvd
- github.com/envoyproxy/gateway/pull/9171nvd
- github.com/envoyproxy/gateway/pull/9172nvd
- github.com/envoyproxy/gateway/pull/9173nvd
- github.com/envoyproxy/gateway/releases/tag/v1.7.4nvd
- github.com/envoyproxy/gateway/releases/tag/v1.8.1nvd
News mentions
0No linked articles in our index yet.