Impact
The vulnerability originates from Envoy Gateway’s handling of custom backendRef extensions. In the custom-backend branch, the function that validates the backend namespace is omitted, allowing an HTTPRoute in one namespace to bind to a backend resource in another namespace without a matching ReferenceGrant. This omission results in an authorization bypass, granting the owner of the HTTPRoute accidental access to resources in a different namespace. The flaw violates the Gateway API cross‑namespace authorization model and matches a missing‑authorization weakness. Consequently, an attacker who can create or modify HTTPRoutes could expose or manipulate backend services across namespaces, jeopardizing confidentiality and integrity.
Affected Systems
The affected product is Envoy Gateway (vendor envoyproxy:gateway). Versions prior to 1.7.4 and prior to 1.8.1 are vulnerable; upgrading to 1.7.4 or 1.8.1 removes the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is less than 1%, reflecting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. The attack requires access to the Kubernetes API to create or edit HTTPRoute objects, making it a privileged‑access attack rather than a publicly reachable one. If an attacker gains permission to modify HTTPRoute resources, the bypass can be exploited to access or redirect traffic to unintended backend services across namespaces. The risk remains moderate, contingent on the attacker’s ability to interact with the cluster API.
OpenCVE Enrichment
Github GHSA