PT-2026-60688 · Unknown · Envoy Gateway
CVE-2026-53716
·
Published
2026-07-16
·
Updated
2026-07-30
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Envoy Gateway (affected versions not specified)
Description
An issue exists in the Wasm HTTP fetch mechanism where the
getFileFromGZ function calls io.ReadAll on a raw gzip.Reader without an output bound. While the compressed input is capped at 256 MiB, the lack of a decompression limit allows an untrusted tenant to provide a specially crafted gzip file (gzip-bomb) via the EnvoyExtensionPolicy.spec.wasm[].code.http.url parameter. This can lead to excessive memory allocation in the shared controller process, resulting in Out-of-Memory (OOM) kills, crash-loops, and a persistent control-plane outage affecting multiple tenants.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envoy Gateway