20 Total advisories
20 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/envoyproxy/gateway is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-53719
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway
MEDIUM 6.5
CVE-2026-53719
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
UNKNOWN
CVE-2026-53716
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway
MEDIUM 6.5
CVE-2026-53716
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
UNKNOWN
CVE-2026-53718
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway
MEDIUM 6.4
CVE-2026-53718
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
UNKNOWN
CVE-2026-53713
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway
CRITICAL 9.1
CVE-2026-53713
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
UNKNOWN
CVE-2026-53717
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway
MEDIUM 6.5
CVE-2026-53717
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
UNKNOWN
CVE-2026-53714
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway
HIGH 7.4
CVE-2026-53714
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
UNKNOWN
CVE-2026-53715
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway
MEDIUM 5.3
CVE-2026-53715
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
HIGH 8.8
CVE-2026-22771
Envoy Extension Policy lua scripts injection causes arbitrary command execution
MEDIUM 5.3
CVE-2025-25294
Envoy Gateway Log Injection Vulnerability
HIGH 7.1
CVE-2025-24030
Envoy Admin Interface Exposed through prometheus metrics endpoint
UNKNOWN
CVE-2025-24030
Envoy Admin Interface Exposed through prometheus metrics endpoint in github.com/envoyproxy/gateway
UNKNOWN
CVE-2025-25294
Envoy Gateway Log Injection Vulnerability in github.com/envoyproxy/gateway
UNKNOWN
CVE-2026-22771
Envoy Extension Policy lua scripts injection causes arbitrary command execution in github.com/envoyproxy/gateway
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes