CVE-2025-64323

Source
https://cve.org/CVERecord?id=CVE-2025-64323
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64323.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64323
Aliases
Published
2025-11-07T03:18:48.993Z
Modified
2026-07-15T01:49:18.368807216Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
kgateway is missing xDS authorization
Details

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.

Database specific
{
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64323.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/kgateway-dev/kgateway

Affected ranges

Type
GIT
Repo
https://github.com/kgateway-dev/kgateway
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.1.0-agw-cel-rbac"
        },
        {
            "fixed": "2.1.0-rc.2"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

v2.*
v2.1.0-main
v2.1.0-rc.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64323.json"