Feed/CVE-2026-53719
CVE-2026-53719MEDIUMCVSS 6.5

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

Published Jul 16, 2026·Updated Jul 16, 2026

NVD Description

Vulnerability report without repro case. Repro case may be added later after harness is complete. **Preconditions (4):** - Tenant has SecurityPolicy + TCPRoute RBAC (baseline) - Tenant namespace permitted to attach TCPRoute to a Gateway listener - spec.authorization omitted (the trigger) - No admission webhook blocks the shape **Description:** A namespace-scoped tenant can deterministically panic the gatewayapi runner on every reconcile with a single CRD; the recover() in message/watchutil.go:53 keeps the process alive but unwinds the entire handle() callback in runner/runner.go:192, so xDS/Infra IR publishing stalls controller-wide until an admin deletes the object. Data plane keeps serving last-good config.

Affected Packages (1)

github.com/envoyproxy/gatewayGO
From 1.8.0-rc.0
Fixed in 1.8.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free