Skip to main content
EPSS 0.6%top 52%

CVE-2026-22771: CWE-94: Improper Control of Generation of Code ('Code Injection') in envoyproxy gateway

0
High
VulnerabilityCVE-2026-22771cvecve-2026-22771cwe-94
Published: 01/12/2026 (01/12/2026, 18:08:22 UTC)
Source: CVE Database V5
Vendor/Project: envoyproxy
Product: gateway

Description

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

envoyproxy

gateway

Affected versions
<1.5.7>=1.6.0-rc.0 <1.6.2
GitHub Actionsmore threats →ai
envoyproxy/gateway
pkg:github/envoyproxy/gateway
Affected versions
<1.5.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 08:34:34 UTC

Technical Analysis

Envoy Gateway versions before 1.5.7 and 1.6.2 contain a code injection vulnerability (CWE-94) in the EnvoyExtensionPolicy Lua scripting feature. This flaw allows malicious Lua scripts to leak the proxy's credentials, which can then be used to access the control plane. With control plane access, an attacker can retrieve all sensitive secrets managed by Envoy proxy, such as TLS private keys and credentials for downstream and upstream communication. The vulnerability has a CVSS 3.1 base score of 8.8, indicating high severity. Official fixes are available in versions 1.5.7 and 1.6.2. The Red Hat advisory confirms the vulnerability and remediation.

Potential Impact

Successful exploitation leads to credential leakage from the Envoy proxy, enabling unauthorized access to the control plane. This access compromises all secrets used by the proxy, including TLS private keys and communication credentials, potentially allowing attackers to intercept or manipulate secure communications and gain further control over the system.

Mitigation Recommendations

Upgrade Envoy Gateway to version 1.5.7 or later (including 1.6.2 or later) where this vulnerability is fixed. The Red Hat advisory confirms that these versions contain the official fix. No additional mitigation is required if these versions are deployed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-01-09T18:27:19.387Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-22771","vendor":"Red Hat"}]

Threat ID: 69653c31da2266e838f5b98e

Added to database: 01/12/2026, 18:23:45 UTC

Last enriched: 07/15/2026, 08:34:34 UTC

Last updated: 09/10/2026, 22:26:40 UTC

Views: 374

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses