Impact
Envoy Gateway, an open‑source gateway for Envoy Proxy, processes tenant‑supplied image URLs defined in EnvoyExtensionPolicy.spec.wasm[].code.image.url to fetch OCI or Docker Wasm layers. The image fetcher uses the untrusted tar‑header field h.Size to pre‑allocate a byte slice before validating the entry name or declared size. A malicious small PAX or GNU tar header can claim a multi‑terabyte size, yet only the limited bytes read by the surrounding LimitReader are available. Because there is no registry allowlist, a tenant can target an attacker‑controlled registry reachable by the controller. The allocation is attempted for every tar entry and can trigger an unrecoverable Go runtime out‑of‑memory failure. The custom resource persists, causing reconciliation to repeatedly crash‑loop the shared controller, leading to a single non‑volumetric request that results in a cluster‑wide control‑plane denial of service. This vulnerability is fixed in Envoy Gateway versions 1.7.4 and 1.8.1.
Affected Systems
Envoy Gateway versions prior to 1.7.4 and 1.8.1 are affected. The vulnerability is tied to the internal/wasm/imagefetcher.go implementation that follows tenant‑controlled EnvoyExtensionPolicy.spec.wasm[].code.image.url values to fetch OCI layers. Any deployment that allows tenants to specify arbitrary image URLs without a registry allowlist could be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker who can supply a malicious OCI image through a tenant‑controlled URL—enabled by the absence of a registry allowlist—can trigger the out‑of‑memory error. The resulting controller crash‑loop disrupts the entire control plane, leading to a denial of service that affects the whole cluster. The attack vector is inferred to be from tenant‑supplied image URLs; no privileged access or special user permissions beyond tenant control are required.
OpenCVE Enrichment
Github GHSA