Security: envoyproxy/gateway
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassGHSA-fcrp-7gc2-93g7 published
Jun 5, 2026 by zirainModerate -
Wasm cache ServeHTTP reads mappingPath2Cache without lockGHSA-8fv2-88gg-hm7q published
Jun 5, 2026 by zirainModerate -
Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationGHSA-m2v6-2jmh-4c68 published
Jun 5, 2026 by zirainModerate -
OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerGHSA-h7pq-86h8-rp5x published
Jun 5, 2026 by zirainModerate -
Wasm HTTP fetch decompresses gzip without output-size limitGHSA-cxpq-8v7q-cg56 published
Jun 5, 2026 by zirainModerate -
Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret DisclosureGHSA-wcrf-9vrr-854f published
Jun 5, 2026 by zirainCritical -
xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceModeGHSA-22xc-xg2r-9j7v published
Jun 5, 2026 by zirainHigh -
Envoy Gateway arbitrary code execution through EnvoyExtensionPolicy Lua scriptsGHSA-xrwg-mqj6-6m22 published
Jan 12, 2026 by guydcHigh -
Log Injection VulnerabilityGHSA-mf24-chxh-hmvj published
Mar 6, 2025 by guydcModerate -
Envoy Admin Interface Exposed through prometheus metrics endpointGHSA-j777-63hf-hx76 published
Jan 23, 2025 by arkodgHigh