VYPR
Medium severityNVD Advisory· Published Jul 16, 2026

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

CVE-2026-53719

Description

Vulnerability report without repro case. Repro case may be added later after harness is complete.

Preconditions (4): - Tenant has SecurityPolicy + TCPRoute RBAC (baseline) - Tenant namespace permitted to attach TCPRoute to a Gateway listener - spec.authorization omitted (the trigger) - No admission webhook blocks the shape

Description:

A namespace-scoped tenant can deterministically panic the gatewayapi runner on every reconcile with a single CRD; the recover() in message/watchutil.go:53 keeps the process alive but unwinds the entire handle() callback in runner/runner.go:192, so xDS/Infra IR publishing stalls controller-wide until an admin deletes the object. Data plane keeps serving last-good config.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/envoyproxy/gatewayGo
>= 1.8.0-rc.0, < 1.8.11.8.1
github.com/envoyproxy/gatewayGo
< 1.7.41.7.4

Affected products

35

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.