CVE-2026-53718: CWE-862: Missing Authorization in envoyproxy gateway
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the target namespace. The custom-backend branch in internal/gatewayapi/route.go omits validateBackendNamespace, allowing the route-owning namespace to bind to and use the resource without the backend namespace owner's consent and violating the Gateway API cross-namespace authorization model. This issue is fixed in versions 1.7.4 and 1.8.1.
AI Analysis
Technical Summary
Envoy Gateway versions before 1.7.4 and between 1.8.0-rc.0 and 1.8.1 contain a missing authorization check (CWE-862) in the handling of HTTPRoute objects that use extension-managed custom backendRef references. Specifically, the custom-backend branch in internal/gatewayapi/route.go omits the validateBackendNamespace function, allowing a route-owning namespace to bind to and use backend resources in other namespaces without the target namespace owner's consent. This violates the Gateway API's intended cross-namespace authorization model. The vulnerability is resolved in versions 1.7.4 and 1.8.1.
Potential Impact
An attacker with the ability to create or modify HTTPRoute objects can reference backend resources in namespaces they do not own or control, bypassing intended authorization controls. This can lead to unauthorized access to backend resources, resulting in high confidentiality impact, low integrity impact, and low availability impact as per the CVSS vector.
Mitigation Recommendations
Upgrade Envoy Gateway to version 1.7.4 or later, or to version 1.8.1 or later. These versions include the fix that enforces proper cross-namespace authorization checks. No other mitigation is indicated by the vendor advisory.
CVE-2026-53718: CWE-862: Missing Authorization in envoyproxy gateway
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API ReferenceGrant in the target namespace. The custom-backend branch in internal/gatewayapi/route.go omits validateBackendNamespace, allowing the route-owning namespace to bind to and use the resource without the backend namespace owner's consent and violating the Gateway API cross-namespace authorization model. This issue is fixed in versions 1.7.4 and 1.8.1.
CVSS v3.1
Score 6.4medium
Affected software
envoyproxy
gateway
pkg:github/envoyproxy/gatewayRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Envoy Gateway versions before 1.7.4 and between 1.8.0-rc.0 and 1.8.1 contain a missing authorization check (CWE-862) in the handling of HTTPRoute objects that use extension-managed custom backendRef references. Specifically, the custom-backend branch in internal/gatewayapi/route.go omits the validateBackendNamespace function, allowing a route-owning namespace to bind to and use backend resources in other namespaces without the target namespace owner's consent. This violates the Gateway API's intended cross-namespace authorization model. The vulnerability is resolved in versions 1.7.4 and 1.8.1.
Potential Impact
An attacker with the ability to create or modify HTTPRoute objects can reference backend resources in namespaces they do not own or control, bypassing intended authorization controls. This can lead to unauthorized access to backend resources, resulting in high confidentiality impact, low integrity impact, and low availability impact as per the CVSS vector.
Mitigation Recommendations
Upgrade Envoy Gateway to version 1.7.4 or later, or to version 1.8.1 or later. These versions include the fix that enforces proper cross-namespace authorization checks. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-10T16:43:31.241Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa85d5955bf5e2cf598a220
Added to database: 09/14/2026, 20:47:21 UTC
Last enriched: 09/14/2026, 21:02:15 UTC
Last updated: 09/15/2026, 05:09:52 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.