PT-2026-60689 · Unknown · Envoy Gateway

CVE-2026-53717

·

Published

2026-07-16

·

Updated

2026-07-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy Gateway (affected versions not specified)
Description An issue exists during OCI layer extraction where the system allocates memory using make([]byte, h.Size) based on the size declared in a tar header. Because the LimitReader only bounds the bytes read from the stream and not the size declared in the header, an attacker can use PAX/GNU encoding to claim a multi-terabyte entry. This is reachable via the spec.wasm[].code.image.url parameter in the EnvoyExtensionPolicy resource. The resulting Out-of-Memory (OOM) error is unrecoverable and causes the shared controller to enter a crash-loop, leading to a cluster-wide Denial of Service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53717
GHSA-H7PQ-86H8-RP5X
GO-2026-6008
OPENSUSE-SU-2026:21483-1

Affected Products

Envoy Gateway