CVE-2026-22771 Details
Description
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.
A vulnerability exists in Envoy Gateway versions prior to 1.5.7 and 1.6.2, allowing EnvoyExtensionPolicy Lua scripts executed by Envoy proxy to leak the proxy's credentials. These credentials can be used to communicate with the control plane and access all secrets utilized by Envoy proxy, such as TLS private keys and credentials for downstream and upstream communication. The vulnerability arises from the ability of Lua scripts in EnvoyExtensionPolicy resources to access sensitive files, including XDS client certificates and Kubernetes service account tokens, which can lead to arbitrary code execution in the Envoy Gateway controller pod and privilege escalation.
Users can update to Envoy Gateway versions 1.5.7 or 1.6.2, where this vulnerability has been fixed. Additionally, Kubernetes RBAC rules can be implemented to restrict the creation of EnvoyExtensionPolicy resources with Lua scripts to trusted namespaces.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-22771 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2428735 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22771.json | redhat-SADP | |
| https://github.com/envoyproxy/gateway/security/advisories/GHSA-xrwg-mqj6-6m22 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | redhat-SADP |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| envoyproxy gateway | < 1.5.7 >= 1.6.0, < 1.6.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | Initial Analysis | [email protected] |
| Jan 12, 2026 | New CVE Received | [email protected] |