Impact
The vulnerability resides in the translateSecurityPolicyForRoute function of Envoy Gateway, which dereferences a nil authorization value when a namespace‑scoped tenant creates a SecurityPolicy that targets a TCPRoute and omits the spec.authorization field. Each reconciliation of the persistent object triggers a panic; the controller recovers, but this unwinds critical callback handlers, stalling controller‑wide xDS and intermediate‑representation publishing until an administrator deletes the affected object. During this stall the data plane continues to serve the last known good configuration. The flaw is fixed in versions 1.7.4 and 1.8.1 and is identified as CWE‑476.
Affected Systems
Envoy Gateway is affected when using versions prior to 1.7.4 or 1.8.1. The flaw appears in the internal/gatewayapi/securitypolicy.go component, impacting any cluster that deploys the open source project without the patch. All users of these versions are at risk until the artifacts are updated to a fixed release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score of <1% indicates a very low exploitation probability. The likely attack vector is that a tenant with permission to create or modify a SecurityPolicy object triggers the vulnerability; once triggered, the panic stalls controller activity until remediation. This remains a local‑to‑cluster privilege (typically an administrator or privileged namespace contributor) rather than an external remote exploit.
OpenCVE Enrichment
Github GHSA