PT-2026-60688 · Unknown · Envoy Gateway

CVE-2026-53716

·

Published

2026-07-16

·

Updated

2026-07-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy Gateway (affected versions not specified)
Description An issue exists in the Wasm HTTP fetch mechanism where the getFileFromGZ function calls io.ReadAll on a raw gzip.Reader without an output bound. While the compressed input is capped at 256 MiB, the lack of a decompression limit allows an untrusted tenant to provide a specially crafted gzip file (gzip-bomb) via the EnvoyExtensionPolicy.spec.wasm[].code.http.url parameter. This can lead to excessive memory allocation in the shared controller process, resulting in Out-of-Memory (OOM) kills, crash-loops, and a persistent control-plane outage affecting multiple tenants.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53716
GHSA-CXPQ-8V7Q-CG56
GO-2026-6006
OPENSUSE-SU-2026:21483-1

Affected Products

Envoy Gateway