Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22771

Опубликовано: 12 янв. 2026
Источник: redhat
CVSS3: 8.8

Описание

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.

A flaw was found in Envoy Gateway. EnvoyExtensionPolicy Lua scripts, when executed by the Envoy proxy, can be exploited to leak the proxy's credentials. An attacker can then use these credentials to communicate with the control plane and gain unauthorized access to all secrets managed by the Envoy proxy, including sensitive TLS private keys. This vulnerability leads to critical information disclosure, potentially compromising the security of communications.

Отчет

Red Hat products do not contain the affected components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Connectivity Link 1rhcl-1/rhcl-operator-bundleNot affected
Red Hat Connectivity Link 1rhcl-1/rhcl-rhel9-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2428735envoyproxy/gateway: Envoy Gateway: Unauthorized access to secrets via Lua script credential leakage

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.

CVSS3: 8.8
github
3 месяца назад

Envoy Extension Policy lua scripts injection causes arbitrary command execution

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость компонента EnvoyExtensionPolicy программной платформы для управления Envoy Proxy Envoy Gateway, позволяющая нарушителю выполнить произвольный код

8.8 High

CVSS3