CyberRota Analysis
AI-GeneratedKubernetes users utilizing Envoy Gateway versions prior to 1.7.4 and 1.8.1 are vulnerable to a nil dereference issue in the SecurityPolicy handling, which can cause a panic during reconciliation when a TCPRoute lacks an authorization specification. This results in stalled xDS and infrastructure publishing, potentially impacting service availability, although the data plane will continue to operate with the last known good configuration. Administrators managing Kubernetes environments should prioritize upgrading to the patched versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a SecurityPolicy targeting a TCPRoute and omits spec.authorization. The persistent object triggers the panic on every reconcile; recovery in message/watchutil.go keeps the process alive but unwinds the runner/runner.go handle callback, stalling controller-wide xDS and infrastructure intermediate-representation publishing until an administrator deletes the object. The data plane continues to serve the last known good configuration while publication is stalled. This issue is fixed in versions 1.7.4 and 1.8.1.