go

github.com/envoyproxy/gateway

View on go registry
20 Total advisories
20 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/envoyproxy/gateway is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-53719

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway

MEDIUM 6.5
Go

CVE-2026-53719

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

UNKNOWN
Go

CVE-2026-53716

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway

MEDIUM 6.5
Go

CVE-2026-53716

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

UNKNOWN
Go

CVE-2026-53718

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway

MEDIUM 6.4
Go

CVE-2026-53718

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

UNKNOWN
Go

CVE-2026-53713

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway

CRITICAL 9.1
Go

CVE-2026-53713

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

UNKNOWN
Go

CVE-2026-53717

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway

MEDIUM 6.5
Go

CVE-2026-53717

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

UNKNOWN
Go

CVE-2026-53714

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway

HIGH 7.4
Go

CVE-2026-53714

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

UNKNOWN
Go

CVE-2026-53715

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway

MEDIUM 5.3
Go

CVE-2026-53715

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

HIGH 8.8
Go

CVE-2026-22771

Envoy Extension Policy lua scripts injection causes arbitrary command execution

MEDIUM 5.3
Go

CVE-2025-25294

Envoy Gateway Log Injection Vulnerability

HIGH 7.1
Go

CVE-2025-24030

Envoy Admin Interface Exposed through prometheus metrics endpoint

UNKNOWN
Go

CVE-2025-24030

Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway

UNKNOWN
Go

CVE-2025-25294

Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway

UNKNOWN
Go

CVE-2026-22771

Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes