Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Calico HIGH 7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re…

Fix: 3.21.7 / 3.22.4+
Fix from $1,950 2026-07-30
Calico HIGH 7.5
CVE-2026-41186

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug lis…

Fix: 3.21.7 / 3.22.4+
Fix from $1,950 2026-07-30
Calico MEDIUM 6.5
CVE-2026-41187

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,…

Fix: 3.21.7 / 3.22.4+
Fix from $1,600 2026-07-30
Calico MEDIUM 6.5
CVE-2026-41184

In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEA…

Fix: 3.21.7 / 3.22.3+
Fix from $1,600 2026-05-28
Calico MEDIUM 6.5
CVE-2026-41185

When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information befor…

Fix: 3.21.7 / 3.22.3+
Fix from $1,600 2026-05-28
Calico Cloud HIGH 7.5
CVE-2023-41378

In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS …

Fix: 3.15.4 / 3.16.4+
Fix from $1,950 2023-11-06
Calico MEDIUM 5.5
CVE-2022-28224

Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floatin…

Fix: 3.11.4 / 3.20.5+
Fix from $1,600 2022-06-06