CVE-2026-53716
CVE-2026-53716: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-53716] Denial of Service via uncontrolled gzip decompression of Wasm HTTP fetch
CVE-2026-53716Source published Source updated
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip. Reader without limiting decompressed output when a tenant-controlled EnvoyExtensionPolicy.spec.wasm[].code.http.url points to a reachable compressed Wasm payload. The 256 MiB compressed-input cap does not constrain the expanded size, no operator Wasm URL allowlist exists, and the optional sha256 check occurs only after decompression, so a comparatively small gzip stream can force a multi-gigabyte allocation in the shared controller. The resulting out-of-memory termination restarts the controller, re-reconciles the persistent custom resource, and can create a persistent…
- Affected products in this advisory
- Red Hat Connectivity Link 1
- Source-reported affected versions
- < 1.7.4
- < 1.8.1
- Source-reported fixed versions
- 1.7.4
- 1.8.1
- Mitigation guidance
- Restrict creation of EnvoyExtensionPolicy resources and constrain operator access to approved Wasm URLs until an updated Envoy Gateway version is available.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.