CVE-2026-53717
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.71%
- CWE
- CWE-789
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- envoyproxy gateway
- envoyproxy gateway
Weakness type
Related vulnerabilities
- CVE-2026-25579 — Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
- CVE-2026-5740 — Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
- CVE-2026-28253 — Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
- CVE-2025-54801 — Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder
- CVE-2026-49975 — Apache HTTP Server: mod_http2 denial of service
- CVE-2026-22803 — SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer
- CVE-2026-22026 — CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion
- CVE-2026-82435 — Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder