CVE-2026-22771: CWE-94: Improper Control of Generation of Code ('Code Injection') in envoyproxy gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.
AI Analysis
Technical Summary
Envoy Gateway versions before 1.5.7 and 1.6.2 contain a code injection vulnerability (CWE-94) in the EnvoyExtensionPolicy Lua scripting feature. This flaw allows malicious Lua scripts to leak the proxy's credentials, which can then be used to access the control plane. With control plane access, an attacker can retrieve all sensitive secrets managed by Envoy proxy, such as TLS private keys and credentials for downstream and upstream communication. The vulnerability has a CVSS 3.1 base score of 8.8, indicating high severity. Official fixes are available in versions 1.5.7 and 1.6.2. The Red Hat advisory confirms the vulnerability and remediation.
Potential Impact
Successful exploitation leads to credential leakage from the Envoy proxy, enabling unauthorized access to the control plane. This access compromises all secrets used by the proxy, including TLS private keys and communication credentials, potentially allowing attackers to intercept or manipulate secure communications and gain further control over the system.
Mitigation Recommendations
Upgrade Envoy Gateway to version 1.5.7 or later (including 1.6.2 or later) where this vulnerability is fixed. The Red Hat advisory confirms that these versions contain the official fix. No additional mitigation is required if these versions are deployed.
CVE-2026-22771: CWE-94: Improper Control of Generation of Code ('Code Injection') in envoyproxy gateway
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.
CVSS v3.1
Score 8.8high
Affected software
envoyproxy
gateway
pkg:github/envoyproxy/gatewayRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Envoy Gateway versions before 1.5.7 and 1.6.2 contain a code injection vulnerability (CWE-94) in the EnvoyExtensionPolicy Lua scripting feature. This flaw allows malicious Lua scripts to leak the proxy's credentials, which can then be used to access the control plane. With control plane access, an attacker can retrieve all sensitive secrets managed by Envoy proxy, such as TLS private keys and credentials for downstream and upstream communication. The vulnerability has a CVSS 3.1 base score of 8.8, indicating high severity. Official fixes are available in versions 1.5.7 and 1.6.2. The Red Hat advisory confirms the vulnerability and remediation.
Potential Impact
Successful exploitation leads to credential leakage from the Envoy proxy, enabling unauthorized access to the control plane. This access compromises all secrets used by the proxy, including TLS private keys and communication credentials, potentially allowing attackers to intercept or manipulate secure communications and gain further control over the system.
Mitigation Recommendations
Upgrade Envoy Gateway to version 1.5.7 or later (including 1.6.2 or later) where this vulnerability is fixed. The Red Hat advisory confirms that these versions contain the official fix. No additional mitigation is required if these versions are deployed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-01-09T18:27:19.387Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-22771","vendor":"Red Hat"}]
Threat ID: 69653c31da2266e838f5b98e
Added to database: 01/12/2026, 18:23:45 UTC
Last enriched: 07/15/2026, 08:34:34 UTC
Last updated: 09/10/2026, 22:26:40 UTC
Views: 374
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.