Answer in brief
CVE-2026-53717 records a Medium severity (CVSS 6.5) vulnerability in Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header. The current sources do not mark it as known exploited. The current feed maps envoyproxy/gateway (generic), github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps envoyproxy/gateway (generic), github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| envoyproxy/gatewaygeneric | < 1.7.4 || >= 1.8.0-rc.0, < 1.8.1 | Not reported |
| github.com/envoyproxy/gatewaygo | >=1.8.0-rc.0,<1.8.1 | 1.8.1 |
| github.com/envoyproxy/gatewaygo | <1.7.4 | 1.7.4 |
| github.com/envoyproxy/gatewaygo | >=1.8.0-rc.0 <1.8.1 | 1.8.1 |
| github.com/envoyproxy/gatewaygo | >=0 <1.7.4 | 1.7.4 |
Published upstream
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 16, 2026
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extractWasmPluginBinary uses the untrusted tar-header h.Size value to allocate memory before validating the entry name or declared size. A small PAX or GNU tar header can therefore claim a multi-terabyte entry even though the surrounding LimitReader restricts only the bytes read from the stream, and no registry allowlist prevents a permitted tenant from selecting an attacker-controlled registry that the controller can reach. The allocation is attempted for every tar entry and can cause an unrecoverable Go runtime out-of-memory failure; because the custom resource persists, reconciliation repeatedly crash-loops the shared controller and causes a single-request, non-volumetric, cluster-wide control-plane denial of service. This issue is fixed in versions 1.7.4 and 1.8.1.
Quoted source text, attributed separately from HOL analysis.