CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-fcrp-7gc2-93g7: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

mediumCVSS 6.4CVE-2026-53718
Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource. Patches 1.7.4 1.8.1

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 6.4
Published
2026-07-16
Last updated
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-fcrp-7gc2-93g7

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-53718coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories