Skip to content
VulniPulse
Advisory severityMedium6.5Red Hat Linux

Medium [CVE-2026-53716] Denial of Service via uncontrolled gzip decompression of Wasm HTTP fetch

This medium-severity Red Hat Linux advisory covers CVE-2026-53716 affecting Red Hat Connectivity Link 1.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-53716 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.

Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload.

The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller.

The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent cross-tenant control-plane outage. This issue is fixed in versions 1.7.4 and 1.8.1.

A remote attacker, by providing a specially crafted compressed WebAssembly (Wasm) payload through a tenant-controlled URL, can exploit a vulnerability where the system decompresses the gzip file without limiting the output size. This can lead to an uncontrolled memory allocation, causing the controller to terminate due to out-of-memory conditions.

The resulting restarts can cause a persistent denial of service across multiple tenants. RH Connectivity Link includes an affected Envoy Gateway version.

Affected versions
  • < 1.7.4
  • < 1.8.1

Official advisory · high-confidence parse· fetched 1 day ago·verify at source

Fixed versions
  • 1.7.4
  • 1.8.1

Official advisory · high-confidence parse· fetched 1 day ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Restrict creation of EnvoyExtensionPolicy resources and constrain operator access to approved Wasm URLs until an updated Envoy Gateway version is available.

Official advisory · high-confidence parse· fetched 1 day ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.