« Volver al listado

CVE-2026-53717

Estado: Pendiente de análisisMedia (6.5)—

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size.

Leer descripción completaMostrar menos

A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53717",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-53717",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-15T19:29:49.750607Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "envoyproxy",
          "product": "gateway",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.7.4"
            },
            {
              "status": "affected",
              "version": ">= 1.8.0-rc.0, < 1.8.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-14T20:16:45.270",
  "references": [
    {
      "url": "https://github.com/envoyproxy/gateway/commit/5a78db82b7cf4fc5bebbeda2c50952892038a464",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/commit/96e2b750868a459ace4b8b68e6a6e4fb0152b9b7",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/commit/b4737180c7e597490c6363075c565fa8cf24eead",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/pull/9171",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/pull/9172",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/pull/9173",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/releases/tag/v1.7.4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/releases/tag/v1.8.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-789"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1."
    }
  ],
  "lastModified": "2026-09-30T17:43:24.057",
  "sourceIdentifier": "security-advisories@github.com"
}