GHSA-m2v6-2jmh-4c68MediumCVSS 6.5

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

Published
July 16, 2026
Last Modified
July 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Vulnerability report without repro case. Repro case may be added later after harness is complete.

Preconditions (4):

  • Tenant has SecurityPolicy + TCPRoute RBAC (baseline)
  • Tenant namespace permitted to attach TCPRoute to a Gateway listener
  • spec.authorization omitted (the trigger)
  • No admission webhook blocks the shape

Description:

A namespace-scoped tenant can deterministically panic the gatewayapi runner on every reconcile with a single CRD; the recover() in message/watchutil.go:53 keeps the process alive but unwinds the entire handle() callback in runner/runner.go:192, so xDS/Infra IR publishing stalls controller-wide until an admin deletes the object. Data plane keeps serving last-good config.

🎯 Affected products2

  • go/github.com/envoyproxy/gateway:>= 1.8.0-rc.0, < 1.8.1
  • go/github.com/envoyproxy/gateway:< 1.7.4

🔗 References (2)