📦

gateway

Vendor: aviatrix

Actively Exploited 2 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 3 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 21.69% Exploit Prob.
Latest CVE CVE-2026-22771 Jan 12

Security Vulnerability Index

Page 1 / 1
8.8 CVSS

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate with the control plane and gain access to all secrets that are used by Envoy proxy, e.g. TLS private keys and credentials used for downstream and upstream communication. This vulnerability is fixed in 1.5.7 and 1.6.2.

EPSS: 0.57%
6.9 CVSS

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

EPSS: 0.33%
5.3 CVSS

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This format is vulnerable to log injection attacks. If the attacker uses a specially crafted user-agent which performs json injection, then he could add and overwrite fields to the access log. This vulnerability is fixed in 1.3.1 and 1.2.7. One can overwrite the old text based default format with JSON formatter by modifying the "EnvoyProxy.spec.telemetry.accessLog" setting.

EPSS: 0.26%
7.1 CVSS

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

EPSS: 0.41%
6.1 CVSS

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

EPSS: 80.91%
6.3 CVSS

Arbitrary file read in Citrix ADC and Citrix Gateway 

EPSS: 1.07%
7.5 CVSS

Unauthenticated denial of service

EPSS: 1.02%
6.5 CVSS

Authenticated denial of service

EPSS: 0.99%
6.5 CVSS

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

EPSS: 0.58%
9.8 CVSS
CVE-2022-27518
Exploit Found

Unauthenticated remote arbitrary code execution

EPSS: 6.93%