Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-6540 Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re… Calico 3.21.7 / 3.22.4+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-41186 When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug lis… Calico 3.21.7 / 3.22.4+ Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-41187 Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy,… Calico 3.21.7 / 3.22.4+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-41184 In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEA… Calico 3.21.7 / 3.22.3+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-41185 When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information befor… Calico 3.21.7 / 3.22.3+ Fix from $1,6002026-05-28 HIGH 7.5 CVE-2023-41378 In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS … Calico Cloud 3.15.4 / 3.16.4+ Fix from $1,9502023-11-06 MEDIUM 5.5 CVE-2022-28224 Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floatin… Calico 3.11.4 / 3.20.5+ Fix from $1,6002022-06-06