BIT-envoy-gateway-2026-53716

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/envoy-gateway/BIT-envoy-gateway-2026-53716.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-envoy-gateway-2026-53716
Aliases
Published
2026-09-21T08:54:57Z
Modified
2026-09-21T09:40:46Z
Summary
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Details

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload. The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller. The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:envoyproxy:gateway:*:*:*:*:*:go:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / envoy-gateway

Package

Name
envoy-gateway
Purl
pkg:bitnami/envoy-gateway

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.4
Introduced
1.8.0
Fixed
1.8.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/envoy-gateway/BIT-envoy-gateway-2026-53716.json"