Impact
The vulnerability arises when the Envoy Gateway xDS gRPC server is configured for GatewayNamespaceMode. The server installs a JWT StreamInterceptor but no UnaryInterceptor, leaving every unary Fetch RPC unauthenticated. The streaming interceptor authenticates only discoveryv3.DeltaDiscoveryRequest messages; a discoveryv3.DiscoveryRequest used by the State‑of‑the‑World protocol fails the type assertion and returns success without JWT validation. Any pod that can reach port 18000 can use these unprotected paths to retrieve TLS private keys through StreamSecrets, all xDS resources through StreamAggregatedResources, backend endpoints through StreamClusters or StreamEndpoints, and routing configuration through StreamRoutes or StreamListeners. This issue is fixed in versions 1.7.4 and 1.8.1.
Affected Systems
The affected software is the Envoy Gateway project from envoyproxy. Versions prior to 1.7.4 and 1.8.1 are impacted when configured with provider.kubernetes.deploy.type=GatewayNamespace. The vulnerability is not limited to a particular operating system but applies to any deployment of these versions in a Kubernetes or standalone environment where the gRPC server is exposed on port 18000.
Risk and Exploitability
The CVSS score of 7.4 classifies the vulnerability as high‑severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers must be able to reach port 18000, meaning the risk is scoped to internal network or misconfigured exposed services. Once an attacker can reach the endpoint, the lack of authentication enables direct retrieval of sensitive keys and configuration data with no additional privileges.
OpenCVE Enrichment
Github GHSA