Medium [CVE-2026-53716] Denial of Service via uncontrolled gzip decompression of Wasm HTTP fetch
This medium-severity Red Hat Linux advisory covers CVE-2026-53716 affecting Red Hat Connectivity Link 1.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.
Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload.
The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller.
The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.
A remote attacker, by providing a specially crafted compressed WebAssembly (Wasm) payload through a tenant-controlled URL, can exploit a vulnerability where the system decompresses the gzip file without limiting the output size. This can lead to an uncontrolled memory allocation, causing the controller to terminate due to out-of-memory conditions.
The resulting restarts can cause a persistent denial of service across multiple tenants. RH Connectivity Link includes an affected Envoy Gateway version.
- < 1.7.4
- < 1.8.1
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
- 1.7.4
- 1.8.1
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Mitigation checklist
- Restrict creation of EnvoyExtensionPolicy resources and constrain operator access to approved Wasm URLs until an updated Envoy Gateway version is available.
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.