Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xrwg-mqj6-6m22 Envoy Extension Policy lua scripts injection causes arbitrary command execution
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 13 Jan 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Envoyproxy
Envoyproxy gateway
Vendors & Products Envoyproxy
Envoyproxy gateway

Mon, 12 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.
Title Envoy Extension Policy lua scripts injection causes arbitrary command execution
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-12T18:49:19.868Z

Reserved: 2026-01-09T18:27:19.387Z

Link: CVE-2026-22771

cve-icon Vulnrichment

Updated: 2026-01-12T18:49:15.888Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-12T19:16:03.470

Modified: 2026-01-13T14:03:18.990

Link: CVE-2026-22771

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-12T18:08:22Z

Links: CVE-2026-22771 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-13T09:27:08Z

Weaknesses