CVE-2026-53714 is a high-severity vulnerability affecting github.com/envoyproxy/gateway versions >= 1.8.0-rc.0, < 1.8.1 affecting github.com/envoyproxy/gateway versions < 1.7.4 with a CVSS score of 7.4, affecting the Envoy Gateway when operating in GatewayNamespaceMode. This flaw type, CWE-306, allows unauthenticated access to sensitive information, including TLS private keys and backend endpoints, via the State-of-the-World (SotW) xDS protocol. Any pod in the cluster that can reach the xDS server on port 18000 can exploit this vulnerability, resulting in a high business impact due to potential data exposure and unauthorized access. The vulnerability occurs because the JWT authentication interceptor only validates tokens for specific gRPC messages, allowing unauthenticated access to sensitive resources such as TLS private keys, xDS resources, backend endpoints, and routing rules.
We recommend you to update Envoy Gateway to version 1.8.1 or 1.7.4.[/subscribe_to_unlock_form]
CVE-2026-53714 is a high-severity vulnerability affecting github.com/envoyproxy/gateway versions >= 1.8.0-rc.0, < 1.8.1 affecting github.com/envoyproxy/gateway versions < 1.7.4 with a CVSS score of 7.4, affecting the Envoy Gateway when operating in GatewayNamespaceMode. This flaw type, CWE-306, allows unauthenticated access to sensitive information, including TLS private keys and backend endpoints, via the State-of-the-World (SotW) xDS protocol. Any pod in the cluster that can reach the xDS server on port 18000 can exploit this vulnerability, resulting in a high business impact due to potential data exposure and unauthorized access. The vulnerability occurs because the JWT authentication interceptor only validates tokens for specific gRPC messages, allowing unauthenticated access to sensitive resources such as TLS private keys, xDS resources, backend endpoints, and routing rules.
We recommend you to update Envoy Gateway to version 1.8.1 or 1.7.4.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]