CRITICAL9.1CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure >= 1.8.0-rc.0, < 1.8.1
HIGH7.4CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode >= 1.8.0-rc.0, < 1.8.1
HIGH7.1CVE-2025-24030Envoy Admin Interface Exposed through prometheus metrics endpoint from 0, < 1.2.6
HIGH7.1Envoy Admin Interface Exposed through prometheus metrics endpoint
from 0, < 1.2.6
MEDIUM6.5Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
>= 1.8.0-rc.0, < 1.8.1
MEDIUM6.5Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
>= 1.8.0-rc.0, < 1.8.1
MEDIUM6.5Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
>= 1.8.0-rc.0, < 1.8.1
MEDIUM6.4Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
>= 1.8.0-rc.0, < 1.8.1
MEDIUM5.3Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
>= 1.8.0-rc.0, < 1.8.1
MEDIUM5.3Envoy Gateway Log Injection Vulnerability
from 0, < 1.2.7
MEDIUM5.3Envoy Gateway Log Injection Vulnerability
from 0, < 1.2.7, >= 1.3.0-rc.1, < 1.3.1