External risk intelligence

Envoy Gateway Path Traversal Vulnerability Allows Arbitrary File Reading

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-53713

Envoy Gateway functions as an internet-facing application gateway and edge service. Because it is specifically designed to manage traffic at the network edge and is commonly deployed to handle external requests, the vulnerable component is situated in a position where it is frequently exposed to public-facing traffic in standard configurations.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Envoy Gateway that could allow unauthorized access to sensitive files on the gateway controller pod, such as service account tokens or TLS certificates. This could potentially expose credentials, granting access to Kubernetes API Server or Gateway xDS server information.

  • Allows reading sensitive files from gateway systems.
  • Matters due to potential credential exposure.
  • Confirm relevance and exposure of Envoy Gateway.

Attack Path

How an attacker could exploit the issue

An attacker with limited access could exploit this vulnerability by submitting specially crafted Lua code through an EnvoyExtensionPolicy. The validation process for paths in this code does not correctly handle redundant separators, allowing the Lua code to bypass security checks. This bypass enables the attacker to read sensitive files from the gateway controller pod, potentially exposing credentials that could grant access to critical Kubernetes or xDS server information.

  • Requires authenticated access.
  • Triggered by malformed path in Lua code.
  • Allows arbitrary file read of sensitive data.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, submitted Lua code could allow an attacker with low privileges to read arbitrary files from the gateway controller pod. This could expose sensitive information such as Kubernetes service-account tokens, TLS certificates, and process environment data. The disclosed credentials may grant access to the Kubernetes API Server or Gateway xDS server.

  • Gateway controller pod files at risk.
  • Malicious Lua code bypasses validation.
  • Credentials may expose sensitive services.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership for this issue likely resides with platform or infrastructure teams managing the Envoy Gateway, with oversight from security teams. The first practical step is to identify all instances of Envoy Gateway, confirm their exposure and business criticality, and then coordinate remediation with the accountable application or service owners.

  • Platform/infrastructure teams own the issue.
  • Verify Envoy Gateway exposure and criticality.
  • Plan targeted remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Envoy Gateway?

Envoy Gateway is an open-source tool used to manage Envoy Proxy as an application gateway, often deployed in Kubernetes environments. It acts as the traffic controller at the edge of a network, routing and securing requests to services. By simplifying complex configuration tasks, it helps teams manage connectivity and security policies for their cloud-native applications.

How does CVE-2026-53713 enable file access?

This vulnerability, classified as Improper Input Validation (CWE-20), involves a flaw in path processing. The system fails to normalize paths containing redundant separators before verifying them. Because the underlying Linux system interprets these paths differently than the validation logic, an attacker can bypass security checks to read arbitrary files from the gateway controller pod.

Does any input trigger this flaw?

No. The issue is specifically triggered when a user submits malicious Lua code via an EnvoyExtensionPolicy. It relies on path strings that include redundant separators to confuse the validator. If an EnvoyExtensionPolicy does not contain such crafted, malformed paths, the validator correctly blocks restricted access attempts.

Is my deployment at risk according to Halo Surface Signal?

Halo Surface Signal identifies that Envoy Gateway is typically deployed as an internet-facing edge service. Because its core function is managing traffic at the network perimeter, it is frequently exposed to external requests. If your instance is positioned at the network edge, it is in a location where this vulnerability could be reached by outside traffic.

What is the first step to remediate this?

Infrastructure and platform teams should immediately inventory all active Envoy Gateway instances to verify their current version. Since this issue is resolved in versions 1.7.4 and 1.8.1, the primary response is to plan and execute an upgrade for any instance running a version earlier than these releases to secure the controller pod against unauthorized file access.

References