CVE-2026-53713
Last modified
CVE-2026-53713 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. Linux resolves a double-slash absolute path as the corresponding single-slash path, but the validator does not match the redundant-separator form, allowing submitted Lua to read arbitrary files from the gateway controller pod. Exposed files can include Kubernetes service-account tokens, TLS certificates, and process environment data, and the disclosed credentials can provide access to sensitive Kubernetes API Server or Gateway xDS server information. This issue is fixed in versions 1.7.4 and 1.8.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | gateway | < 1.7.4; >= 1.8.0-rc.0, < 1.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-53713?
How severe is CVE-2026-53713?
How do I fix CVE-2026-53713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53705A flaw was found in GStreamer's WavPack audio decoder in gst…7.6
- CVE-2026-53706PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstr…8.8
- CVE-2026-53708ContextForge is an AI gateway, registry, and proxy that prov…6.6
- CVE-2026-5371The MonsterInsights – Google Analytics Dashboard for WordPre…7.1
- CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for …10
- CVE-2026-53712SCRAM (Salted Challenge Response Authentication Mechanism) i…8.2
- CVE-2026-53714Envoy Gateway is an open source project for managing Envoy P…7.4
- CVE-2026-53715Envoy Gateway is an open source project for managing Envoy P…5.3
- CVE-2026-53716Envoy Gateway is an open source project for managing Envoy P…6.5
- CVE-2026-53717Envoy Gateway is an open source project for managing Envoy P…6.5
- CVE-2026-53718Envoy Gateway is an open source project for managing Envoy P…6.4
- CVE-2026-53719Envoy Gateway is an open source project for managing Envoy P…6.5
Are you affected by CVE-2026-53713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
