github.com/envoyproxy/gateway
Manages Envoy Proxy as a Standalone or Kubernetes-based Application Gateway
Activity
- Latest release
- Jul 08, 2026
- Total releases
- 50
- Cadence
- ~15 days
- Last 12 months
- 25
Reach
- Stars
- 2.9k
Details
- First release
- May 13, 2022
| Version | Released | |
|---|---|---|
v1.7.5
patch
|
v1.7.5
patch
Dependencies (85)
+ 77 more |
|
v1.7.4
patch
|
v1.7.4
patch
Dependencies (85)
+ 77 more |
|
v1.8.1
minor
|
v1.8.1
minor
Dependencies (75)
+ 67 more |
|
v1.7.3
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (85)
+ 77 more |
|
v1.8.0-rc.1
pre
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.8.0-rc.1
pre
Dependencies (75)
+ 67 more |
|
v1.9.0-rc.0
pre
|
v1.9.0-rc.0
pre
Dependencies (75)
+ 67 more |
|
v1.6.7
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.6.7
patch
Dependencies (84)
+ 76 more |
|
v1.7.2
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (85)
+ 77 more |
|
v1.6.6
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.6.6
patch
Dependencies (84)
+ 76 more |
|
v1.8.0-rc.0
pre
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.8.0-rc.0
pre
Dependencies (74)
+ 66 more |
|
v1.7.1
minor
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.7.1
minor
Dependencies (85)
+ 77 more |
|
v1.5.9
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.9
patch
Dependencies (81)
+ 73 more |
|
v1.7.0-rc.2
pre
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.7.0-rc.2
pre
Dependencies (84)
+ 76 more |
|
v1.6.3
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.6.3
patch
Dependencies (83)
+ 75 more |
|
v1.7.0-rc.0
pre
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.7.0-rc.0
pre
Dependencies (84)
+ 76 more |
|
v1.6.2
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (83)
+ 75 more |
|
v1.5.7
patch
7 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (81)
+ 73 more |
|
v1.6.1
minor
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (83)
+ 75 more |
|
v1.4.7
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.7
patch
Dependencies (80)
+ 72 more |
|
v1.4.6
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.6
patch
Dependencies (80)
+ 72 more |
|
v1.5.4
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.4
patch
Dependencies (81)
+ 73 more |
|
v1.5.3
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.3
patch
Dependencies (81)
+ 73 more |
|
v1.5.2
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.2
patch
Dependencies (81)
+ 73 more |
|
v1.4.4
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (80)
+ 72 more |
|
v1.5.0
minor
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (81)
+ 73 more |
|
v1.5.0-rc.1
pre
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.5.0-rc.1
pre
Dependencies (81)
+ 73 more |
|
v1.4.1
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (80)
+ 72 more |
|
v1.4.0
minor
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (80)
+ 72 more |
|
v1.4.0-rc.1
pre
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc.1
pre
Dependencies (79)
+ 71 more |
|
v1.3.2
patch
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (76)
+ 68 more |
|
v1.3.1
minor
8 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (75)
+ 67 more |
|
v1.3.0-rc.1
pre
9 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0-rc.1
pre
Dependencies (71)
+ 63 more |
|
v1.2.4
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (67)
+ 59 more |
|
v1.1.4
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (63)
+ 55 more |
|
v1.2.2
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (67)
+ 59 more |
|
v1.2.1
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (67)
+ 59 more |
|
v1.2.0
minor
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (67)
+ 59 more |
|
v1.1.3
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (63)
+ 55 more |
|
v1.2.0-rc.1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (67)
+ 59 more |
|
v1.1.2
patch
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (63)
+ 55 more |
|
v1.1.0
minor
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (63)
+ 55 more |
|
v1.0.1
major
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (49)
+ 41 more |
|
v1.0.0-rc.1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.1
pre
Dependencies (46)
+ 38 more |
|
v0.6.0-rc.1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.0-rc.1
pre
Dependencies (44)
+ 36 more |
|
v0.5.0-rc.1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.5.0-rc.1
pre
Dependencies (36)
+ 28 more |
|
v0.4.0
minor
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (28)
+ 20 more |
|
v0.4.0-rc.1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.0-rc.1
pre
Dependencies (28)
+ 20 more |
|
v0.2.0
minor
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (20)
+ 12 more |
|
v0.2.0-rc1
pre
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.2.0-rc1
pre
Dependencies (19)
+ 11 more |
|
v0.1.0
initial
10 CVEs
CVE-2026-53714
GO-2026-6003
GHSA-22xc-xg2r-9j7v
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53713
GO-2026-6011
GHSA-wcrf-9vrr-854f
Jul 17, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53719
GO-2026-6009
GHSA-m2v6-2jmh-4c68
Jul 17, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53717
GO-2026-6008
GHSA-h7pq-86h8-rp5x
Jul 17, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53718
GO-2026-6007
GHSA-fcrp-7gc2-93g7
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53716
GO-2026-6006
GHSA-cxpq-8v7q-cg56
Jul 17, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53715
GO-2026-6005
GHSA-8fv2-88gg-hm7q
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway Fixed in
1.7.4
1.8.1
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-22771
GO-2026-4312
BIT-envoy-gateway-2026-22771
GHSA-xrwg-mqj6-6m22
Jan 23, 2026
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway Fixed in
1.5.7
1.6.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-25294
GO-2025-3504
BIT-envoy-gateway-2025-25294
GHSA-mf24-chxh-hmvj
Mar 10, 2025
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway Fixed in
1.2.7
1.3.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-24030
GO-2025-3418
BIT-envoy-gateway-2025-24030
GHSA-j777-63hf-hx76
Jan 28, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway Fixed in
1.2.6
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.1.0
initial
|