CVE Tools

Gateway

90 CVEs tracked. 6 of them are in CISA KEV.

This hub aggregates every CVE we track for Gateway, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Gateway CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gateway CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-011
2025-020
2025-031
2025-040
2025-050
2025-062
2025-070
2025-083
2025-090
2025-100
2025-111
2025-121
2026-011
2026-020
2026-033
2026-040
2026-050
2026-066
2026-070
2026-083
2026-097

Severity

How the 90 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1618%
  • High3843%
  • Medium3439%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gateway.

  1. CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode7.4
  2. CVE-2026-53716Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit6.5
  3. CVE-2026-53715Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock5.3
  4. CVE-2026-53719Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization6.5
  5. CVE-2026-53718Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass6.4
  6. CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure9.1
  7. CVE-2026-53717Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header6.5
  8. CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*7.5
  9. CVE-2026-19490NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-194909.8
  10. CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.—
  11. CVE-2026-13474Denial of service via malformed HTTP/2 requests7.5
  12. CVE-2026-10817Insufficient input validation leading to memory overread7.5
  13. CVE-2026-10816Arbitrary File Read (Unauthenticated)7.5
  14. CVE-2026-8655Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service9.8
  15. CVE-2026-8452Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store