GHSA-fcrp-7gc2-93g7MediumCVSS 6.4
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
🔗 CVE IDs covered (1)
📋 Description
Impact
Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource.
Patches
🎯 Affected products2
- go/github.com/envoyproxy/gateway:>= 1.8.0-rc.0, < 1.8.1
- go/github.com/envoyproxy/gateway:< 1.7.4