Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer.Get writes the same map during EnvoyExtensionPolicy translation. An attacker with pod-network access to unauthenticated port 18002 and tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a per-request reader overlaps a writer. Go's concurrent map read and write detection invokes runtime.throw, which the net/http connection recovery cannot catch, terminating the controller process and causing a timing-dependent, cross-tenant control-plane denial of service until Kubernetes restarts the pod. This issue is fixed in versions 1.7.4 and 1.8.1.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑tenant control‑plane denial of service
Action: Immediate Patch
AI Analysis

Impact

Envoy Gateway contains a concurrency bug in its Wasm cache system. Prior to versions 1.7.4 and 1.8.1 the HTTP server reads the mappingPath2Cache map without a lock while another routine writes to the same map during EnvoyExtensionPolicy translation. An attacker who can reach the gateway’s unauthenticated port 18002 and has tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a reader overlaps a writer. Go’s runtime detects the concurrent map access, triggers runtime.throw, and the net/http connection recovery cannot catch the panic. As a result the controller process terminates, causing a timing‑dependent, cross‑tenant control‑plane denial of service until Kubernetes restarts the pod. The flaw is a data‑race bug (CWE‑362) and is fixed in 1.7.4 and 1.8.1.

Affected Systems

The issue affects Envoy Gateway versions prior to 1.7.4 and 1.8.1. Attackers must have network access to the gateway’s unauthenticated port 18002 and tenant permissions that allow them to churn EnvoyExtensionPolicy objects with distinct Wasm URLs, which triggers the reading and writing of the shared map.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. To exploit the vulnerability an attacker must be able to flood GET requests to the gateway’s unauthenticated port 18002 and possess the tenant permissions to create or modify EnvoyExtensionPolicy objects pointing to distinct Wasm URLs; this is achievable by an internal or compromised tenant. EPSS is < 1% and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires ordinary network traffic and is timing‑dependent, it may cause intermittent outages, but the lack of a public exploit and the mitigations around pod‑network access limit the threat window.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envoy Gateway to version 1.7.4 or newer, or to 1.8.1 or newer, which includes the required synchronization changes.
  • If upgrading immediately is not possible, restrict traffic to port 18002 to trusted sources or block untrusted GET requests until the patch is applied.
  • Enforce stricter tenant permissions so only authorized roles can churn policies that reference Wasm modules; consider disabling or limiting dynamic Wasm loading until the outgoing issue is resolved.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8fv2-88gg-hm7q Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer.Get writes the same map during EnvoyExtensionPolicy translation. An attacker with pod-network access to unauthenticated port 18002 and tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a per-request reader overlaps a writer. Go's concurrent map read and write detection invokes runtime.throw, which the net/http connection recovery cannot catch, terminating the controller process and causing a timing-dependent, cross-tenant control-plane denial of service until Kubernetes restarts the pod. This issue is fixed in versions 1.7.4 and 1.8.1.
Title Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Envoyproxy Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:35:21.990Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53715

cve-icon Vulnrichment

Updated: 2026-09-15T14:26:13.077Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:12.833

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-53715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')