Impact
A flaw in Envoy Gateway’s Lua validation logic allows an attacker to submit Lua scripts that reference paths containing redundant separators. Because the path normalization step does not collapse double slashes before the critical check, the validator accepts the path and the embedded Lua can read arbitrary files from the gateway controller pod. The disclosed files may contain Kubernetes service‑account tokens, TLS certificates, or environment data, enabling an attacker to gain credentials that provide further access to the Kubernetes API Server or the Gateway xDS server.
Affected Systems
The vulnerability affects Envoy Gateway versions prior to 1.7.4 and 1.8.1. All releases before these patch releases are at risk, while the latest versions include the fix reported in the release notes.
Risk and Exploitability
With a CVSS score of 9.1 the vulnerability is classified as high severity. The EPSS score is <1%, and the issue is not listed in the CISA KEV catalog, although the lack of a publicly known exploit does not preclude local or remote exploitation. The likely attack vector involves an entity that can submit an EnvoyExtensionPolicy (e.g., an administrative user or an API consumer with policy‑creation privileges). By delivering a malicious Lua script through the policy, the attacker can read sensitive files and achieve credential disclosure or further privilege escalation.
OpenCVE Enrichment
Github GHSA