VYPR
Medium severityNVD Advisory· Published Jul 16, 2026

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

CVE-2026-53718

Description

Impact

Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource.

Patches

1.7.4 1.8.1

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/envoyproxy/gatewayGo
>= 1.8.0-rc.0, < 1.8.11.8.1
github.com/envoyproxy/gatewayGo
< 1.7.41.7.4

Affected products

35

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.