Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the target namespace. The custom-backend branch in internal/gatewayapi/route.go omits validateBackendNamespace, allowing the route-owning namespace to bind to and use the resource without the backend namespace owner's consent and violating the Gateway API cross-namespace authorization model. This issue is fixed in versions 1.7.4 and 1.8.1.
Published: 2026-09-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-namespace Authorization Bypass
Action: Patch Upgrade
AI Analysis

Impact

The vulnerability originates from Envoy Gateway’s handling of custom backendRef extensions. In the custom-backend branch, the function that validates the backend namespace is omitted, allowing an HTTPRoute in one namespace to bind to a backend resource in another namespace without a matching ReferenceGrant. This omission results in an authorization bypass, granting the owner of the HTTPRoute accidental access to resources in a different namespace. The flaw violates the Gateway API cross‑namespace authorization model and matches a missing‑authorization weakness. Consequently, an attacker who can create or modify HTTPRoutes could expose or manipulate backend services across namespaces, jeopardizing confidentiality and integrity.

Affected Systems

The affected product is Envoy Gateway (vendor envoyproxy:gateway). Versions prior to 1.7.4 and prior to 1.8.1 are vulnerable; upgrading to 1.7.4 or 1.8.1 removes the flaw.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score is less than 1%, reflecting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. The attack requires access to the Kubernetes API to create or edit HTTPRoute objects, making it a privileged‑access attack rather than a publicly reachable one. If an attacker gains permission to modify HTTPRoute resources, the bypass can be exploited to access or redirect traffic to unintended backend services across namespaces. The risk remains moderate, contingent on the attacker’s ability to interact with the cluster API.

Generated by OpenCVE AI on September 20, 2026 at 22:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envoy Gateway to version 1.7.4 or newer 1.8.1.
  • Ensure custom backendRef usage is constrained to the owning namespace or validated by ReferenceGrant objects.
  • Limit RBAC permissions so that only trusted roles can create or patch HTTPRoute resources.
  • Audit HTTPRoute definitions for suspicious cross‑namespace backendRef references and investigate anomalies.

Generated by OpenCVE AI on September 20, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fcrp-7gc2-93g7 Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the target namespace. The custom-backend branch in internal/gatewayapi/route.go omits validateBackendNamespace, allowing the route-owning namespace to bind to and use the resource without the backend namespace owner's consent and violating the Gateway API cross-namespace authorization model. This issue is fixed in versions 1.7.4 and 1.8.1.
Title Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Envoyproxy Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:55:25.432Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53718

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:23.152Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:13.140

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-53718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses