Security releases of Envoy Gateway 1.6.2 and 1.5.7 are now available

4 views
Skip to first unread message

Guy Daich

unread,
Jan 12, 2026, 12:29:19 PM (4 days ago) Jan 12
to envoy-gateway-announce

Hello Envoy Gateway Community,

The Envoy Gateway security team would like to announce the availability of Envoy Gateway 1.6.2 and 1.5.7.

This addresses the following CVE(s):

  • CVE-2026-22771 (CVSS score 8.8/10 - High) Envoy Gateway arbitrary code execution through EnvoyExtensionPolicy Lua scripts

Upgrading to 1.6.2 and 1.5.7 is encouraged to fix this issue.

For more information about fixed vulnerability please see the following link:

Thanks,

Guy Daich on behalf of the Envoy Gateway security team and maintainers. 

Reply all
Reply to author
Forward
0 new messages