Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload. The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller. The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Envoy Gateway's Wasm HTTP fetcher expands gzip data without restricting the decompressed size when a tenant provides a writable EnvoyExtensionPolicy.spec.wasm[].code.http.url. The getFileFromGZ routine reads the entire payload via io.ReadAll on a gzip.Reader, allowing a small compressed stream to allocate several gigabytes of memory. Because the compressed‑input cap of 256 MiB does not constrain the expanded size, a tenant can trigger an out‑of‑memory termination of the shared controller. Since there is no operator Wasm URL allowlist and the optional SHA‑256 verification occurs only after decompression, any tenant can supply a malicious URL. The controller restarts automatically, re‑reconciles the custom resource, and can create a persistent cross‑tenant outage. The flaw is a classic memory‑allocation weakness (CWE‑789) that can cause denial of service to all workloads routed through the affected Envoy Proxy.

Affected Systems

The vulnerability affects all releases of Envoy Gateway older than v1.7.4 and v1.8.1, whether deployed as a standalone or in Kubernetes mode. Operators can trigger the flaw by configuring a tenant‑controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url that points to a gzip‑compressed Wasm payload, since no allowlist exists and the optional SHA‑256 verification is performed only after decompression.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability poses a moderate severity threat. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, but the attack path is relatively straightforward for a tenant that can define the Wasm URL. A malicious actor can trigger the unchecked decompression to exhaust memory, disrupt shared controller services, and cause a denial of service that affects other tenants. The impact is confined to the control plane of the gateway, yet it can be leveraged to deny service to all workloads routed through the affected Envoy Proxy.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envoy Gateway to version 1.7.4 or later, or 1.8.1 or later, to apply the patched getFileFromGZ implementation.
  • Implement an allowlist for acceptable Wasm URLs or restrict the EnvoyExtensionPolicy resource so that only trusted sources are permitted to deploy Wasm code.
  • If an upgrade is unavailable, configure resource limits on the Wasm fetch process to prevent large memory allocations, or disable the HTTP fetch capability for Wasm loading.
  • Consider monitoring memory usage and controller health metrics to detect potential OOM events early and react before a service disruption occurs.

Generated by OpenCVE AI on September 20, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cxpq-8v7q-cg56 Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload. The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller. The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.
Title Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Envoyproxy Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:21:20.674Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53716

cve-icon Vulnrichment

Updated: 2026-09-16T16:21:15.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:12.983

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value