BIT-envoy-gateway-2026-53719

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/envoy-gateway/BIT-envoy-gateway-2026-53719.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-envoy-gateway-2026-53719
Aliases
Published
2026-09-21T08:55:01Z
Modified
2026-09-21T09:40:47Z
Summary
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Details

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. The persistent object triggers the panic on every reconcile; recovery in message/watchutil.go keeps the process alive but unwinds the runner/runner.go handle callback, stalling controller-wide xDS and infrastructure intermediate-representation publishing until an administrator deletes the object. The data plane continues to serve the last known good configuration while publication is stalled. This issue is fixed in versions 1.7.4 and 1.8.1.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:envoyproxy:gateway:*:*:*:*:*:go:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / envoy-gateway

Package

Name
envoy-gateway
Purl
pkg:bitnami/envoy-gateway

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.4
Introduced
1.8.0
Fixed
1.8.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/envoy-gateway/BIT-envoy-gateway-2026-53719.json"