Medium [CVE-2026-53715] Denial of Service via Wasm cache improper synchronization
This medium-severity Red Hat Linux advisory covers CVE-2026-53715 affecting Red Hat Connectivity Link 1.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.
ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer. Get writes the same map during EnvoyExtensionPolicy translation.
An attacker with pod-network access to unauthenticated port 18002 and tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a per-request reader overlaps a writer.
Go's concurrent map read and write detection invokes runtime.throw, which the net/http connection recovery cannot catch, terminating the controller process and causing a timing-dependent, cross-tenant control-plane denial of service until Kubernetes restarts the pod. This issue is fixed in versions 1.7.4 and 1.8.1.
Improper synchronization in the Wasm cache handling allows an attacker with pod-network access and tenant permissions to trigger a race condition. By flooding GET requests, an attacker can cause a read-write overlap, leading to the termination of the controller process.
Red Hat Connectivity Link includes an affected Envoy Gateway version below 1.7.4.
Affected product named by the advisory: Red Hat Connectivity Link 1.
- < 1.7.4
- < 1.8.1
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
- 1.7.4
- 1.8.1
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Mitigation checklist
- Restrict pod-network access to port 18002 and limit untrusted tenants' permission to create or modify EnvoyExtensionPolicy resources. These controls reduce exposure but do not eliminate the race for authorized users.
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.