github.com/envoyproxy/gateway vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53714Highgithub.com/envoyproxy/gateway: Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode CVE-2026-53713Criticalgithub.com/envoyproxy/gateway: Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret DisclosureCVE-2026-53715Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lockCVE-2026-53717Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerCVE-2026-53719Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationCVE-2026-53716Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limitCVE-2026-53718Mediumgithub.com/envoyproxy/gateway: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassCVE-2026-22771Highgithub.com/envoyproxy/gateway: Envoy Extension Policy lua scripts injection causes arbitrary command executionCVE-2025-25294Mediumgithub.com/envoyproxy/gateway: Envoy Gateway Log Injection VulnerabilityCVE-2025-24030Highgithub.com/envoyproxy/gateway: Envoy Admin Interface Exposed through prometheus metrics endpoint

Stop the waste.
Protect your environment with Kodem.