CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-m2v6-2jmh-4c68: Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

mediumCVSS 6.5CVE-2026-53719
Vulnerability report without repro case. Repro case may be added later after harness is complete. Preconditions (4): - Tenant has SecurityPolicy + TCPRoute RBAC (baseline) - Tenant namespace permitted to attach TCPRoute to a Gateway listener - spec.authorization omitted (the trigger) - No admission webhook blocks the shape Description: A namespace-scoped tenant can deterministically panic the gatewayapi runner on every reconcile with a single CRD; the recover() in message/watchutil.go:53 keeps the process alive but unwinds the entire handle() callback in runner/runner.go:192, so xDS/Infra IR publishing stalls controller-wide until an admin deletes the object. Data plane keeps serving last-good config.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 6.5
Published
2026-07-16
Last updated
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-m2v6-2jmh-4c68

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-53719coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories