### Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource. ### Patches [1.7.4](https://github.com/envoyproxy/gateway/releases/tag/v1.7.4) [1.8.1](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1)
Update github.com/envoyproxy/gateway to 1.8.1; github.com/envoyproxy/gateway to 1.7.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanEnvoy Gateway custom backendRef cross-namespace ReferenceGrant bypass affects github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go). Severity is medium. ### Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource. ### Patches [1.7.4](https://github.com/envoyproxy/gateway/releases/tag/v1.7.4) [1.8.1](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1)
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/envoyproxy/gateway |
### Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource. ### Patches [1.7.4](https://github.com/envoyproxy/gateway/releases/tag/v1.7.4) [1.8.1](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1)
Update github.com/envoyproxy/gateway to 1.8.1; github.com/envoyproxy/gateway to 1.7.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanEnvoy Gateway custom backendRef cross-namespace ReferenceGrant bypass affects github.com/envoyproxy/gateway (go), github.com/envoyproxy/gateway (go). Severity is medium. ### Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource. ### Patches [1.7.4](https://github.com/envoyproxy/gateway/releases/tag/v1.7.4) [1.8.1](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1)
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/envoyproxy/gateway |
| >=1.8.0-rc.0,<1.8.1 |
| 1.8.1 |
| github.com/envoyproxy/gatewaygo | <1.7.4 | 1.7.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=1.8.0-rc.0,<1.8.1 |
| 1.8.1 |
| github.com/envoyproxy/gatewaygo | <1.7.4 | 1.7.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard