CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53719

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-07-16
Vulnerability report without repro case. Repro case may be added later after harness is complete. Preconditions (4): - Tenant has SecurityPolicy + TCPRoute RBAC (baseline) - Tenant namespace permitted to attach TCPRoute to a Gateway listener - spec.authorization omitted (the trigger) - No admission webhook blocks the shape Description: A namespace-scoped tenant can deterministically panic the gatewayapi runner on every reconcile with a single CRD; the recover() in message/watchutil.go:53 keeps the process alive but unwinds the entire handle() callback in runner/runner.go:192, so xDS/Infra IR publishing stalls controller-wide until an admin deletes the object. Data plane keeps serving last-good config.

⚡ Watch CVE-2026-53719

Get an email if CVE-2026-53719 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-53719

CVE.org record

Embed the live status

CVE-2026-53719 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53719 status](https://www.csirts.com/badge/CVE-2026-53719)](https://www.csirts.com/cve/CVE-2026-53719)