Impact
Envoy Gateway contains a concurrency bug in its Wasm cache system. Prior to versions 1.7.4 and 1.8.1 the HTTP server reads the mappingPath2Cache map without a lock while another routine writes to the same map during EnvoyExtensionPolicy translation. An attacker who can reach the gateway’s unauthenticated port 18002 and has tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a reader overlaps a writer. Go’s runtime detects the concurrent map access, triggers runtime.throw, and the net/http connection recovery cannot catch the panic. As a result the controller process terminates, causing a timing‑dependent, cross‑tenant control‑plane denial of service until Kubernetes restarts the pod. The flaw is a data‑race bug (CWE‑362) and is fixed in 1.7.4 and 1.8.1.
Affected Systems
The issue affects Envoy Gateway versions prior to 1.7.4 and 1.8.1. Attackers must have network access to the gateway’s unauthenticated port 18002 and tenant permissions that allow them to churn EnvoyExtensionPolicy objects with distinct Wasm URLs, which triggers the reading and writing of the shared map.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. To exploit the vulnerability an attacker must be able to flood GET requests to the gateway’s unauthenticated port 18002 and possess the tenant permissions to create or modify EnvoyExtensionPolicy objects pointing to distinct Wasm URLs; this is achievable by an internal or compromised tenant. EPSS is < 1% and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires ordinary network traffic and is timing‑dependent, it may cause intermittent outages, but the lack of a public exploit and the mitigations around pod‑network access limit the threat window.
OpenCVE Enrichment
Github GHSA