# Envoy AI Gateway: enforce limits before buffering

Request limits applied after allocation protect downstream work but may leave the gateway itself exposed to memory exhaustion. Availability depends on where a limit runs, how many bodies can be buffered concurrently and whether cancellation releases the allocated resources.

## What deployment does this concern?

**Component and scope:** MCP POST-body buffering in the external-processing component.

**Affected versions / scope:** 0.4.0 through 0.7.0

**Vendor remediation:** 1.0.0

The affected path reads the full MCP POST body before applying the relevant limits. An authenticated caller may still be able to send a body large enough to exhaust component memory.

## Vendor response and practical action

The vendor identifies 1.0.0 as patched. Upgrade and configure request-size, concurrency and timeout controls at the earliest ingress layer and the processing component.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

## What clients can learn

A small per-request limit is not a complete capacity model. Multiply buffering by admitted concurrency and account for protocol expansion, such as decoding, before choosing a memory budget.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

## Questions to take to your provider

- Where is the body-size limit enforced relative to allocation?
- What is the maximum simultaneously buffered input?
- Do authenticated tenants share the same processing memory?
- How are rejection, cancellation and recovery observed?

Use the [six-page evaluation worksheet](/assets/downloads/ai-gateway-evaluation-worksheet.pdf) to record evidence, ownership and actions. Continue with [AI gateway reliability: define failure before adding fallback](/resources/ai-gateway-reliability) for the wider evaluation context.

### Technical detail: evidence and identifier limits

This is a documented MCP component issue. It is not evidence that all large LLM requests or every Envoy data plane will fail.



Evidence label: **security advisory**. Source-review date: **2026-10-07**. Source publication or event date: **2026-09-26**. These dates do not change merely because this article is rebuilt.

## Primary sources

- [GHSA-43xg-mvg9-qwpq · vendor advisory](https://github.com/theagentrouter/agent-router/security/advisories/GHSA-43xg-mvg9-qwpq)


---
Published: 2026-10-07. Modified: 2026-10-07. Sources reviewed: 2026-10-07.

Author: OneQuill Research. Affiliation: OneQuill develops OneVir. Documentary review; selected case totals are not vendor security rankings.
