github.com/envoyproxy/gateway
Go10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/envoyproxy/gatewaypage 1 of 1
- CVE-2025-24030HIGHCVSS 7.1EG 7.1✓ Fixed in 1.2.62025-01-23
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface command…
- CVE-2025-25294MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.3.12025-03-06
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This f…
- CVE-2026-22771HIGHCVSS 8.8EG 8.8✓ Fixed in 1.6.22026-01-12
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's cr…
- CVE-2026-53713CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not colla…
- CVE-2026-53714HIGHCVSS 7.4EG 7.4✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deploy.…
- CVE-2026-53715MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map w…
- CVE-2026-53716MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without lim…
- CVE-2026-53717MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].co…
- CVE-2026-53718MEDIUMCVSS 6.4EG 6.4✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource…
- CVE-2026-53719MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.8.12026-07-16
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil…
Check whether github.com/envoyproxy/gateway is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/envoyproxy/gateway CVEs against the assets you own.
Start Free Scan →