{"id":"GHSA-h7pq-86h8-rp5x","summary":"Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header","details":"Vulnerability report without repro case. Repro case may be added later after harness is complete.\n\n**Preconditions (4):**\n- Tenant can create EnvoyExtensionPolicy (baseline)\n- Controller has egress to attacker-controlled OCI registry\n- No registry allowlist (none exists in code)\n- Layer presents Docker/OCI media type\n\n**Description**\n\nAt imagefetcher.go:287, make([]byte, h.Size) uses the attacker-controlled tar-header size; the LimitReader at :278 bounds bytes read from the stream but not the header-declared size returned by tr.Next() (a 512-byte header can claim a multi-TB entry via PAX/GNU encoding). Reached from untrusted tenant input via EnvoyExtensionPolicy spec.wasm[].code.image.url (envoyextensionpolicy.go:1157 → cache.go:262/299 → imagefetcher.go:218 → :287), and the allocation happens for every tar entry regardless of filename. The resulting Go runtime OOM throw is unrecoverable and, because the CRD persists, crash-loops the shared controller — single-request, non-volumetric, cluster-wide DoS.","aliases":["BIT-envoy-gateway-2026-53717","CVE-2026-53717","GO-2026-6008"],"modified":"2026-09-21T09:40:44.685630655Z","published":"2026-07-16T19:20:05Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-16T19:20:05Z","nvd_published_at":null,"cwe_ids":["CWE-789"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/envoyproxy/gateway/security/advisories/GHSA-h7pq-86h8-rp5x"},{"type":"PACKAGE","url":"https://github.com/envoyproxy/gateway"}],"affected":[{"package":{"name":"github.com/envoyproxy/gateway","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/gateway"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.8.0-rc.0"},{"fixed":"1.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-h7pq-86h8-rp5x/GHSA-h7pq-86h8-rp5x.json"}},{"package":{"name":"github.com/envoyproxy/gateway","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/gateway"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-h7pq-86h8-rp5x/GHSA-h7pq-86h8-rp5x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}