Security Advisories for github.com/envoyproxy/gateway in go
High
30 days ago
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
go
github.com/envoyproxy/gateway
Critical
30 days ago
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
go
github.com/envoyproxy/gateway
Moderate
30 days ago
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
go
github.com/envoyproxy/gateway
Moderate
30 days ago
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
go
github.com/envoyproxy/gateway
Moderate
30 days ago
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
go
github.com/envoyproxy/gateway
Moderate
30 days ago
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
go
github.com/envoyproxy/gateway
Moderate
30 days ago
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
go
github.com/envoyproxy/gateway
High
7 months ago
Envoy Extension Policy lua scripts injection causes arbitrary command execution
go
github.com/envoyproxy/gateway
High
over 1 year ago
Envoy Admin Interface Exposed through prometheus metrics endpoint
go
github.com/envoyproxy/gateway