Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. The persistent object triggers the panic on every reconcile; recovery in message/watchutil.go keeps the process alive but unwinds the runner/runner.go handle callback, stalling controller-wide xDS and infrastructure intermediate-representation publishing until an administrator deletes the object. The data plane continues to serve the last known good configuration while publication is stalled. This issue is fixed in versions 1.7.4 and 1.8.1.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via controller crash
Action: Immediate patch
AI Analysis

Impact

The vulnerability resides in the translateSecurityPolicyForRoute function of Envoy Gateway, which dereferences a nil authorization value when a namespace‑scoped tenant creates a SecurityPolicy that targets a TCPRoute and omits the spec.authorization field. Each reconciliation of the persistent object triggers a panic; the controller recovers, but this unwinds critical callback handlers, stalling controller‑wide xDS and intermediate‑representation publishing until an administrator deletes the affected object. During this stall the data plane continues to serve the last known good configuration. The flaw is fixed in versions 1.7.4 and 1.8.1 and is identified as CWE‑476.

Affected Systems

Envoy Gateway is affected when using versions prior to 1.7.4 or 1.8.1. The flaw appears in the internal/gatewayapi/securitypolicy.go component, impacting any cluster that deploys the open source project without the patch. All users of these versions are at risk until the artifacts are updated to a fixed release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score of <1% indicates a very low exploitation probability. The likely attack vector is that a tenant with permission to create or modify a SecurityPolicy object triggers the vulnerability; once triggered, the panic stalls controller activity until remediation. This remains a local‑to‑cluster privilege (typically an administrator or privileged namespace contributor) rather than an external remote exploit.

Generated by OpenCVE AI on September 20, 2026 at 22:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Envoy Gateway to version 1.7.4 or later 1.8.1
  • If upgrade is impossible, delete any SecurityPolicy objects that target a TCPRoute and omit spec.authorization until a patch is applied
  • Exclude or validate spec.authorization in SecurityPolicy manifests to prevent nil dereference on creation

Generated by OpenCVE AI on September 20, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m2v6-2jmh-4c68 Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. The persistent object triggers the panic on every reconcile; recovery in message/watchutil.go keeps the process alive but unwinds the runner/runner.go handle callback, stalling controller-wide xDS and infrastructure intermediate-representation publishing until an administrator deletes the object. The data plane continues to serve the last known good configuration while publication is stalled. This issue is fixed in versions 1.7.4 and 1.8.1.
Title Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Envoyproxy Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:10:27.491Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53719

cve-icon Vulnrichment

Updated: 2026-09-16T18:10:24.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:13.307

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses