Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cluster‑wide control‑plane denial of service
Action: Apply Patch
AI Analysis

Impact

Envoy Gateway, an open‑source gateway for Envoy Proxy, processes tenant‑supplied image URLs defined in EnvoyExtensionPolicy.spec.wasm[].code.image.url to fetch OCI or Docker Wasm layers. The image fetcher uses the untrusted tar‑header field h.Size to pre‑allocate a byte slice before validating the entry name or declared size. A malicious small PAX or GNU tar header can claim a multi‑terabyte size, yet only the limited bytes read by the surrounding LimitReader are available. Because there is no registry allowlist, a tenant can target an attacker‑controlled registry reachable by the controller. The allocation is attempted for every tar entry and can trigger an unrecoverable Go runtime out‑of‑memory failure. The custom resource persists, causing reconciliation to repeatedly crash‑loop the shared controller, leading to a single non‑volumetric request that results in a cluster‑wide control‑plane denial of service. This vulnerability is fixed in Envoy Gateway versions 1.7.4 and 1.8.1.

Affected Systems

Envoy Gateway versions prior to 1.7.4 and 1.8.1 are affected. The vulnerability is tied to the internal/wasm/imagefetcher.go implementation that follows tenant‑controlled EnvoyExtensionPolicy.spec.wasm[].code.image.url values to fetch OCI layers. Any deployment that allows tenants to specify arbitrary image URLs without a registry allowlist could be impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker who can supply a malicious OCI image through a tenant‑controlled URL—enabled by the absence of a registry allowlist—can trigger the out‑of‑memory error. The resulting controller crash‑loop disrupts the entire control plane, leading to a denial of service that affects the whole cluster. The attack vector is inferred to be from tenant‑supplied image URLs; no privileged access or special user permissions beyond tenant control are required.

Generated by OpenCVE AI on September 20, 2026 at 22:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envoy Gateway to version 1.7.4 or later (including 1.8.1).
  • Restrict tenant‑supplied image URLs to trusted registries and disallow arbitrary registry access.
  • Add validation to reject tar entries whose header size exceeds a configured safe threshold before allocating memory.

Generated by OpenCVE AI on September 20, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h7pq-86h8-rp5x Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Title Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Envoyproxy Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:30:12.383Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53717

cve-icon Vulnrichment

Updated: 2026-09-15T19:30:01.442Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:45.270

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value