GHSA-fcrp-7gc2-93g7MediumCVSS 6.4

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

Published
July 16, 2026
Last Modified
July 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource.

Patches

1.7.4 1.8.1

🎯 Affected products2

  • go/github.com/envoyproxy/gateway:>= 1.8.0-rc.0, < 1.8.1
  • go/github.com/envoyproxy/gateway:< 1.7.4

🔗 References (2)