Denial of Service Vulnerability in Envoy Gateway by Envoy Proxy
CVE-2026-53717

6.5MEDIUM

Key Information:

Vendor

Envoyproxy

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-53717?

The Envoy Gateway, an open-source project for managing Envoy Proxy, contains a vulnerability that could result in a denial of service. Specifically, the internal image fetching mechanism relies on untrusted sources to allocate memory based on unvalidated tar header sizes, which can lead to out-of-memory failures. This flaw allows an attacker to exploit tenant-controlled parameters, potentially crashing the control plane and disrupting cluster operations. The issue has been addressed in versions 1.7.4 and 1.8.1, and users are advised to upgrade to mitigate the risk. For more details on the vulnerability and its fix, visit the reference links.

Affected Version(s)

gateway < 1.7.4 < 1.7.4

gateway >= 1.8.0-rc.0, < 1.8.1 < 1.8.0-rc.0, 1.8.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.