CVE-2026-53719
Last modified
CVE-2026-53719 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. The persistent object triggers the panic on every reconcile; recovery in message/watchutil.go keeps the process alive but unwinds the runner/runner.go handle callback, stalling controller-wide xDS and infrastructure intermediate-representation publishing until an administrator deletes the object. The data plane continues to serve the last known good configuration while publication is stalled. This issue is fixed in versions 1.7.4 and 1.8.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| envoyproxy | gateway | < 1.7.4; >= 1.8.0-rc.0, < 1.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-53719?
How severe is CVE-2026-53719?
How do I fix CVE-2026-53719?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53713Envoy Gateway is an open source project for managing Envoy P…9.1
- CVE-2026-53714Envoy Gateway is an open source project for managing Envoy P…7.4
- CVE-2026-53715Envoy Gateway is an open source project for managing Envoy P…5.3
- CVE-2026-53716Envoy Gateway is an open source project for managing Envoy P…6.5
- CVE-2026-53717Envoy Gateway is an open source project for managing Envoy P…6.5
- CVE-2026-53718Envoy Gateway is an open source project for managing Envoy P…6.4
- CVE-2026-5372An issue that allowed a SQL injection attack vector related …6.4
- CVE-2026-53720pymonocypher uses cython to wrap the Monocypher C library. P…5.1
- CVE-2026-53721Nuxt is an open-source web development framework for Vue.js.…8.2
- CVE-2026-53722Nuxt is an open-source web development framework for Vue.js.…5.4
- CVE-2026-53723Guzzle Services provides an implementation of the Guzzle Com…5.8
- CVE-2026-53724Parse Server is an open source backend that can be deployed …2.1
Are you affected by CVE-2026-53719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
