Skip to content

feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.2 - #5768

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change OpenSSF
mirror.gcr.io/envoyproxy/gateway-helm (source) minor v1.7.1 → v1.9.2 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

envoyproxy/gateway (mirror.gcr.io/envoyproxy/gateway-helm)

v1.9.2

Compare Source

Release Announcement

Check out the v1.9.2 release announcement to learn more about the release.

v1.9.2

Compare Source

Release Announcement

Check out the v1.9.2 release announcement to learn more about the release.

v1.9.1

Compare Source

Release Announcement

Check out the v1.9.1 release announcement to learn more about the release.

v1.9.1

Compare Source

Release Announcement

Check out the v1.9.1 release announcement to learn more about the release.

v1.9.0

Compare Source

Release Announcement

Check out the v1.9.0 release announcement to learn more about the release.

What's Changed

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 13, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: c33d21b
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway

+++ HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway

@@ -1,9 +1,10 @@

 ---
 apiVersion: v1
 kind: ServiceAccount
+automountServiceAccountToken: false
 metadata:
   name: envoy-gateway
   namespace: ingress
   labels:
     app.kubernetes.io/name: gateway-helm
     app.kubernetes.io/instance: envoy-gateway
--- HelmRelease: ingress/envoy-gateway ConfigMap: ingress/envoy-gateway-config

+++ HelmRelease: ingress/envoy-gateway ConfigMap: ingress/envoy-gateway-config

@@ -22,20 +22,20 @@

     provider:
       kubernetes:
         deploy:
           type: GatewayNamespace
         rateLimitDeployment:
           container:
-            image: mirror.gcr.io/envoyproxy/ratelimit:c8765e89
+            image: mirror.gcr.io/envoyproxy/ratelimit:0482748e
           patch:
             type: StrategicMerge
             value:
               spec:
                 template:
                   spec:
                     containers:
                     - imagePullPolicy: IfNotPresent
                       name: envoy-ratelimit
         shutdownManager:
-          image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+          image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
       type: Kubernetes
 
--- HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-envoy-gateway-role

+++ HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-envoy-gateway-role

@@ -1,12 +1,16 @@

 ---
 apiVersion: rbac.authorization.k8s.io/v1
 kind: ClusterRole
 metadata:
   creationTimestamp: null
   name: envoy-gateway-gateway-helm-envoy-gateway-role
+  labels:
+    app.kubernetes.io/name: gateway-helm
+    app.kubernetes.io/instance: envoy-gateway
+    app.kubernetes.io/managed-by: Helm
 rules:
 - apiGroups:
   - ''
   resources:
   - nodes
   - namespaces
@@ -80,24 +84,26 @@

   - get
   - list
   - watch
 - apiGroups:
   - gateway.envoyproxy.io
   resources:
+  - envoyproxies/status
   - envoypatchpolicies/status
   - clienttrafficpolicies/status
   - backendtrafficpolicies/status
   - securitypolicies/status
   - envoyextensionpolicies/status
   - backends/status
   verbs:
   - update
 - apiGroups:
   - gateway.networking.k8s.io
   resources:
   - gateways
+  - listenersets
   - grpcroutes
   - httproutes
   - referencegrants
   - tcproutes
   - tlsroutes
   - udproutes
@@ -107,32 +113,19 @@

   - list
   - watch
 - apiGroups:
   - gateway.networking.k8s.io
   resources:
   - gateways/status
+  - listenersets/status
   - grpcroutes/status
   - httproutes/status
   - tcproutes/status
   - tlsroutes/status
   - udproutes/status
   - backendtlspolicies/status
-  verbs:
-  - update
-- apiGroups:
-  - gateway.networking.x-k8s.io
-  resources:
-  - xlistenersets
-  verbs:
-  - get
-  - list
-  - watch
-- apiGroups:
-  - gateway.networking.x-k8s.io
-  resources:
-  - xlistenersets/status
   verbs:
   - update
 - apiGroups:
   - ''
   resources:
   - pods
--- HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-cluster-infra-manager

+++ HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-cluster-infra-manager

@@ -18,36 +18,50 @@

   - create
   - get
   - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - apps
   resources:
   - deployments
   - daemonsets
   verbs:
   - create
   - get
+  - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - autoscaling
+  resources:
+  - horizontalpodautoscalers
+  verbs:
+  - create
+  - get
+  - list
+  - delete
+  - deletecollection
+  - patch
+  - watch
+- apiGroups:
   - policy
   resources:
-  - horizontalpodautoscalers
   - poddisruptionbudgets
   verbs:
   - create
   - get
   - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - certificates.k8s.io
   resources:
   - clustertrustbundles
   verbs:
   - list
--- HelmRelease: ingress/envoy-gateway ClusterRoleBinding: ingress/envoy-gateway-gateway-helm-envoy-gateway-rolebinding

+++ HelmRelease: ingress/envoy-gateway ClusterRoleBinding: ingress/envoy-gateway-gateway-helm-envoy-gateway-rolebinding

@@ -1,11 +1,15 @@

 ---
 apiVersion: rbac.authorization.k8s.io/v1
 kind: ClusterRoleBinding
 metadata:
   name: envoy-gateway-gateway-helm-envoy-gateway-rolebinding
+  labels:
+    app.kubernetes.io/name: gateway-helm
+    app.kubernetes.io/instance: envoy-gateway
+    app.kubernetes.io/managed-by: Helm
 roleRef:
   apiGroup: rbac.authorization.k8s.io
   kind: ClusterRole
   name: envoy-gateway-gateway-helm-envoy-gateway-role
 subjects:
 - kind: ServiceAccount
--- HelmRelease: ingress/envoy-gateway Role: ingress/envoy-gateway-gateway-helm-infra-manager

+++ HelmRelease: ingress/envoy-gateway Role: ingress/envoy-gateway-gateway-helm-infra-manager

@@ -19,36 +19,50 @@

   - create
   - get
   - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - apps
   resources:
   - deployments
   - daemonsets
   verbs:
   - create
   - get
+  - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - autoscaling
+  resources:
+  - horizontalpodautoscalers
+  verbs:
+  - create
+  - get
+  - list
+  - delete
+  - deletecollection
+  - patch
+  - watch
+- apiGroups:
   - policy
   resources:
-  - horizontalpodautoscalers
   - poddisruptionbudgets
   verbs:
   - create
   - get
   - list
   - delete
   - deletecollection
   - patch
+  - watch
 - apiGroups:
   - certificates.k8s.io
   resources:
   - clustertrustbundles
   verbs:
   - list
--- HelmRelease: ingress/envoy-gateway Deployment: ingress/envoy-gateway

+++ HelmRelease: ingress/envoy-gateway Deployment: ingress/envoy-gateway

@@ -24,32 +24,56 @@

       labels:
         control-plane: envoy-gateway
         app.kubernetes.io/name: gateway-helm
         app.kubernetes.io/instance: envoy-gateway
         egress.home.arpa/apiserver: allow
     spec:
+      automountServiceAccountToken: true
+      securityContext:
+        fsGroup: 65532
+        runAsGroup: 65532
+        runAsNonRoot: true
+        runAsUser: 65532
+        seccompProfile:
+          type: RuntimeDefault
       containers:
       - args:
         - server
         - --config-path=/config/envoy-gateway.yaml
         env:
         - name: ENVOY_GATEWAY_NAMESPACE
           valueFrom:
             fieldRef:
               apiVersion: v1
               fieldPath: metadata.namespace
+        - name: ENVOY_GATEWAY_SERVICE_ACCOUNT
+          valueFrom:
+            fieldRef:
+              apiVersion: v1
+              fieldPath: spec.serviceAccountName
+        - name: ENVOY_GATEWAY_FULLNAME
+          value: envoy-gateway-gateway-helm
         - name: KUBERNETES_CLUSTER_DOMAIN
           value: cluster.local
-        image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+        image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
         imagePullPolicy: IfNotPresent
+        startupProbe:
+          failureThreshold: 30
+          httpGet:
+            path: /healthz
+            port: 8081
+          periodSeconds: 1
+          successThreshold: 1
+          timeoutSeconds: 1
         livenessProbe:
           httpGet:
             path: /healthz
             port: 8081
-          initialDelaySeconds: 15
           periodSeconds: 20
+          successThreshold: 1
+          timeoutSeconds: 1
         name: envoy-gateway
         ports:
         - containerPort: 18000
           name: grpc
         - containerPort: 18001
           name: ratelimit
@@ -60,44 +84,50 @@

         - name: webhook
           containerPort: 9443
         readinessProbe:
           httpGet:
             path: /readyz
             port: 8081
-          initialDelaySeconds: 5
           periodSeconds: 10
+          successThreshold: 1
+          timeoutSeconds: 1
         resources:
           limits:
             memory: 1024Mi
           requests:
             cpu: 100m
             memory: 256Mi
         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
             - ALL
           privileged: false
+          readOnlyRootFilesystem: true
           runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
         volumeMounts:
         - mountPath: /config
           name: envoy-gateway-config
           readOnly: true
         - mountPath: /certs
           name: certs
           readOnly: true
+        - mountPath: /var/lib/eg/wasm
+          name: wasm-cache
       imagePullSecrets: []
       serviceAccountName: envoy-gateway
       terminationGracePeriodSeconds: 10
       volumes:
       - configMap:
           defaultMode: 420
           name: envoy-gateway-config
         name: envoy-gateway-config
       - name: certs
         secret:
           secretName: envoy-gateway
+      - name: wasm-cache
+        emptyDir: {}
 
--- HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway-gateway-helm-certgen

+++ HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway-gateway-helm-certgen

@@ -1,9 +1,10 @@

 ---
 apiVersion: v1
 kind: ServiceAccount
+automountServiceAccountToken: false
 metadata:
   name: envoy-gateway-gateway-helm-certgen
   namespace: ingress
   labels:
     app.kubernetes.io/name: gateway-helm
     app.kubernetes.io/instance: envoy-gateway
--- HelmRelease: ingress/envoy-gateway Job: ingress/envoy-gateway-gateway-helm-certgen

+++ HelmRelease: ingress/envoy-gateway Job: ingress/envoy-gateway-gateway-helm-certgen

@@ -17,25 +17,33 @@

   template:
     metadata:
       labels:
         app: certgen
         egress.home.arpa/apiserver: allow
     spec:
+      automountServiceAccountToken: true
+      securityContext:
+        fsGroup: 65532
+        runAsGroup: 65532
+        runAsNonRoot: true
+        runAsUser: 65532
+        seccompProfile:
+          type: RuntimeDefault
       containers:
       - command:
         - envoy-gateway
         - certgen
         env:
         - name: ENVOY_GATEWAY_NAMESPACE
           valueFrom:
             fieldRef:
               apiVersion: v1
               fieldPath: metadata.namespace
         - name: KUBERNETES_CLUSTER_DOMAIN
           value: cluster.local
-        image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+        image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
         imagePullPolicy: IfNotPresent
         name: envoy-gateway-certgen
         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             drop:
--- HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicy: ingress/safe-upgrades.gateway.networking.k8s.io

+++ HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicy: ingress/safe-upgrades.gateway.networking.k8s.io

@@ -0,0 +1,44 @@

+---
+apiVersion: admissionregistration.k8s.io/v1
+kind: ValidatingAdmissionPolicy
+metadata:
+  annotations:
+    gateway.networking.k8s.io/bundle-version: v1.6.1
+    gateway.networking.k8s.io/channel: standard
+  name: safe-upgrades.gateway.networking.k8s.io
+spec:
+  failurePolicy: Fail
+  matchConstraints:
+    resourceRules:
+    - apiGroups:
+      - apiextensions.k8s.io
+      apiVersions:
+      - v1
+      operations:
+      - CREATE
+      - UPDATE
+      resources:
+      - '*'
+  validations:
+  - expression: object.spec.group != 'gateway.networking.k8s.io' || oldObject == null
+      || ( has(object.metadata.annotations) && object.metadata.annotations.exists(k,
+      k == 'gateway.networking.k8s.io/channel') && object.metadata.annotations['gateway.networking.k8s.io/channel']
+      == 'standard' ) || ( oldObject != null && has(oldObject.metadata.annotations)
+      && oldObject.metadata.annotations.exists(k, k == 'gateway.networking.k8s.io/channel')
+      && oldObject.metadata.annotations['gateway.networking.k8s.io/channel'] == 'experimental'
+      )
+    message: Installing experimental CRDs on top of standard channel CRDs is prohibited
+      by default. Uninstall ValidatingAdmissionPolicy safe-upgrades.gateway.networking.k8s.io
+      to install experimental CRDs on top of standard channel CRDs.
+    reason: Invalid
+  - expression: |
+      object.spec.group != 'gateway.networking.k8s.io' ||
+      (has(object.metadata.annotations) && object.metadata.annotations.exists(k, k == 'gateway.networking.k8s.io/bundle-version') &&
+      (object.metadata.annotations['gateway.networking.k8s.io/bundle-version'] == 'v0.0.0-dev' ||
+      (object.metadata.annotations['gateway.networking.k8s.io/bundle-version'].startsWith('v1.') &&
+       !matches(object.metadata.annotations['gateway.networking.k8s.io/bundle-version'], '^v1\.[0-4](\.|$)'))))
+    message: Installing CRDs with version other than v0.0.0-dev or v1.5+ is prohibited
+      by default. Uninstall ValidatingAdmissionPolicy safe-upgrades.gateway.networking.k8s.io
+      to install other versions.
+    reason: Invalid
+
--- HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicyBinding: ingress/safe-upgrades.gateway.networking.k8s.io

+++ HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicyBinding: ingress/safe-upgrades.gateway.networking.k8s.io

@@ -0,0 +1,24 @@

+---
+apiVersion: admissionregistration.k8s.io/v1
+kind: ValidatingAdmissionPolicyBinding
+metadata:
+  annotations:
+    gateway.networking.k8s.io/bundle-version: v1.6.1
+    gateway.networking.k8s.io/channel: standard
+  name: safe-upgrades.gateway.networking.k8s.io
+spec:
+  policyName: safe-upgrades.gateway.networking.k8s.io
+  validationActions:
+  - Deny
+  matchResources:
+    resourceRules:
+    - apiGroups:
+      - apiextensions.k8s.io
+      apiVersions:
+      - v1
+      resources:
+      - customresourcedefinitions
+      operations:
+      - CREATE
+      - UPDATE
+

@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from c458be3 to cb5ce34 Compare May 14, 2026 01:01
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.0 feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.0 May 14, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from cb5ce34 to 25152f2 Compare May 15, 2026 18:39
@tinfoild

tinfoild Bot commented May 15, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/ingress/envoy-gateway/app Kustomization: ingress/envoy-gateway-app OCIRepository: ingress/envoy-gateway

+++ kube/deploy/core/ingress/envoy-gateway/app Kustomization: ingress/envoy-gateway-app OCIRepository: ingress/envoy-gateway

@@ -11,9 +11,9 @@

 spec:
   interval: 1h
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: v1.7.1
+    tag: 1.8.3
   url: oci://mirror.gcr.io/envoyproxy/gateway-helm
 

@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 25152f2 to 20c759a Compare June 5, 2026 07:36
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.0 feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.1 Jun 5, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 20c759a to 8268556 Compare June 5, 2026 11:18
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.1 feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.1 Jun 5, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 8268556 to baf855a Compare June 8, 2026 20:59
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from baf855a to ce1eba0 Compare June 19, 2026 12:33
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from ce1eba0 to c71e576 Compare July 1, 2026 07:38
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.1 feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.2 Jul 1, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from c71e576 to b70caa4 Compare July 1, 2026 13:55
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.2 feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.2 Jul 1, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch 2 times, most recently from 09914eb to 2599cfc Compare July 22, 2026 19:17
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.2 feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.3 Jul 22, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 2599cfc to a304e37 Compare July 23, 2026 02:38
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ 1.8.3 feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.3 Jul 23, 2026
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 15:40 SGT
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5768 — feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.3
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 7


Severity Summary

Severity Count
CRITICAL 1
HIGH 1
MEDIUM / MODERATE 5
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 7

Results

Package: mirror.gcr.io/envoyproxy/gateway-helm

  • Ecosystem: Helm (OCI chart — Source: envoyproxy/gateway)
  • Old version: v1.7.1 — VULNERABLE (7 CVEs)
  • New version: v1.8.3 — CLEAN (all fixed in v1.7.4 / v1.8.1)

Vulnerabilities in version v1.7.1

  1. CVE-2026-53713 / GHSA-wcrf-9vrr-854f — Severity: CRITICAL (CVSS 9.1)

    • Description: Authentication bypass via improper input validation in EnvoyExtensionPolicy Lua allows secret disclosure.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-wcrf-9vrr-854f
    • Status: ✅ Fixed in newer versions
  2. CVE-2026-53714 / GHSA-22xc-xg2r-9j7v — Severity: HIGH (CVSS 7.4)

    • Description: xDS Control Plane information disclosure when operating in GatewayNamespaceMode.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-22xc-xg2r-9j7v
    • Status: ✅ Fixed in newer versions
  3. CVE-2026-53718 / GHSA-fcrp-7gc2-93g7 — Severity: MEDIUM (CVSS 6.4)

    • Description: Custom backendRef cross-namespace ReferenceGrant bypass.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-fcrp-7gc2-93g7
    • Status: ✅ Fixed in newer versions
  4. CVE-2026-53719 / GHSA-m2v6-2jmh-4c68 — Severity: MEDIUM (CVSS 6.5)

    • Description: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-m2v6-2jmh-4c68
    • Status: ✅ Fixed in newer versions
  5. CVE-2026-53717 / GHSA-h7pq-86h8-rp5x — Severity: MEDIUM (CVSS 6.5)

    • Description: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-h7pq-86h8-rp5x
    • Status: ✅ Fixed in newer versions
  6. CVE-2026-53716 / GHSA-cxpq-8v7q-cg56 — Severity: MEDIUM (CVSS 6.5)

    • Description: Wasm HTTP fetch decompresses gzip without output-size limit.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-cxpq-8v7q-cg56
    • Status: ✅ Fixed in newer versions
  7. CVE-2026-53715 / GHSA-8fv2-88gg-hm7q — Severity: MEDIUM (CVSS 5.3)

    • Description: Wasm cache ServeHTTP reads mappingPath2Cache without lock.
    • Affected versions: < 1.7.4
    • Fixed in: 1.7.4 / 1.8.1
    • Sources: GHSA, NVD
    • Evidence: GHSA-8fv2-88gg-hm7q
    • Status: ✅ Fixed in newer versions

Vulnerabilities in version v1.8.3

No known vulnerabilities found. All 7 CVEs present in v1.7.1 are fixed in v1.7.4+ or v1.8.1+.

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2026-22771 HIGH 8.8 Lua RCE — patched in 1.6.2, v1.7.1 ≥ 1.6.2 so not affected
CVE-2025-25294 MEDIUM 5.3 Log injection — patched in 1.2.7, neither version affected
CVE-2025-24030 HIGH 7.1 Admin interface exposure — patched in 1.2.6, neither version affected

Changelog Security Highlights (v1.7.1 → v1.8.3)

  • v1.7.4 — Security release fixing 7 CVEs (1 CRITICAL, 1 HIGH, 5 MEDIUM)
  • v1.8.1 — Backport of all 7 security fixes to the v1.8.x series
  • v1.8.3 — Dependency bumps and bug fixes (TLS cert validation, ratelimit config); no new CVEs

Recommendations

  • MERGE PRIORITY: CRITICAL — The old version (v1.7.1) has 1 CRITICAL-severity vulnerability (CVE-2026-53713 — authentication bypass allowing secret disclosure) and 1 HIGH-severity vulnerability (CVE-2026-53714 — xDS info disclosure) that are remediated in v1.8.3.
  • The new version (v1.8.3) introduces no new vulnerabilities — all fixed.
  • Merge this PR as soon as possible to remediate the exposed CRITICAL vulnerability.
  • After merging, consider upgrading to v1.8.x which has active security support.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from a304e37 to 66460bd Compare August 24, 2026 03:07
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.8.3 feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.0 Aug 24, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 66460bd to 4cf1df5 Compare August 28, 2026 21:15
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.0 feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.1 Aug 28, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/mirror.gcr.io-envoyproxy-gateway-helm-1.x branch from 4cf1df5 to c33d21b Compare September 28, 2026 22:20
@tinfoild tinfoild Bot changed the title feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.1 feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.2 Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant