Arbitrary Code Injection Affecting github.com/envoyproxy/gateway/internal/gatewayapi package, versions <1.5.7>=1.6.0-rc.0 <1.6.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.58% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMENVOYPROXYGATEWAYINTERNALGATEWAYAPI-14928057
  • published15 Jan 2026
  • disclosed13 Jan 2026
  • creditRicardo Pchevuzinske Katz, Guy Daich

Introduced: 13 Jan 2026

CVE-2026-22771  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade github.com/envoyproxy/gateway/internal/gatewayapi to version 1.5.7, 1.6.2 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Injection via the EnvoyExtensionPolicy resource. An attacker can execute arbitrary commands and access sensitive credentials by injecting malicious Lua scripts. This can lead to privilege escalation, theft of secrets, and the ability to run or delete resources within the environment.

Workaround

This vulnerability can be mitigated by creating Kubernetes RBAC rules that restrict the creation of these policies to trusted namespaces.

CVSS Base Scores

version 4.0
version 3.1