bit-envoy-gateway-2026-53717

bitnami_vulndb
Description

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "package": {
        "ecosystem": "Bitnami",
        "name": "envoy-gateway",
        "purl": "pkg:bitnami/envoy-gateway"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.7.4"
            },
            {
              "introduced": "1.8.0"
            },
            {
              "fixed": "1.8.1"
            }
          ],
          "type": "SEMVER"
        }
      ],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "type": "CVSS_V3"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-53717"
  ],
  "database_specific": {
    "cpes": [
      "cpe:2.3:a:envoyproxy:gateway:*:*:*:*:*:go:*:*"
    ],
    "severity": "Medium"
  },
  "details": "Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.",
  "id": "BIT-envoy-gateway-2026-53717",
  "modified": "2026-09-21T09:26:48.669Z",
  "published": "2026-09-21T08:54:58.740Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/commit/5a78db82b7cf4fc5bebbeda2c50952892038a464"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/commit/96e2b750868a459ace4b8b68e6a6e4fb0152b9b7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/commit/b4737180c7e597490c6363075c565fa8cf24eead"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/pull/9171"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/pull/9172"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/pull/9173"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/releases/tag/v1.7.4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/releases/tag/v1.8.1"
    },
    {
      "type": "WEB",
      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x"
    },
    {
      "type": "WEB",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53717"
    }
  ],
  "schema_version": "1.6.2",
  "summary": "Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header"
}
View JSON API Download JSON