{"id":"GHSA-fcrp-7gc2-93g7","summary":"Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass","details":"### Impact\nEnvoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the namespace that owns the referenced backend resource does not need to opt in with a ReferenceGrant before another namespace’s HTTPRoute can use that resource.\n\n### Patches\n[1.7.4](https://github.com/envoyproxy/gateway/releases/tag/v1.7.4)\n[1.8.1](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1)","aliases":["BIT-envoy-gateway-2026-53718","CVE-2026-53718","GO-2026-6007"],"modified":"2026-09-21T09:40:46.638359063Z","published":"2026-07-16T19:14:50Z","database_specific":{"cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-16T19:14:50Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/envoyproxy/gateway/security/advisories/GHSA-fcrp-7gc2-93g7"},{"type":"PACKAGE","url":"https://github.com/envoyproxy/gateway"}],"affected":[{"package":{"name":"github.com/envoyproxy/gateway","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/gateway"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.8.0-rc.0"},{"fixed":"1.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fcrp-7gc2-93g7/GHSA-fcrp-7gc2-93g7.json"}},{"package":{"name":"github.com/envoyproxy/gateway","ecosystem":"Go","purl":"pkg:golang/github.com/envoyproxy/gateway"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-fcrp-7gc2-93g7/GHSA-fcrp-7gc2-93g7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"}]}