CVE-2026-6540

Source
https://cve.org/CVERecord?id=CVE-2026-6540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6540
Published
2026-07-30T14:45:04.068Z
Modified
2026-08-01T03:47:22.053149032Z
Severity
  • 7.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L CVSS Calculator
Summary
L7 policy bypass via unnormalized HTTP path matching
Details

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-23"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6540.json",
    "cna_assigner": "Tigera",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.21.7"
                },
                {
                    "fixed": "22.4.0"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/projectcalico/calico

Affected ranges

Type
GIT
Repo
https://github.com/projectcalico/calico
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.31.6"
        },
        {
            "introduced": "3.22.0"
        },
        {
            "fixed": "3.22.4"
        }
    ]
}

Affected versions

v2.*
v2.5.0
v2.5.0-calico
v2.5.0-rc2
v2.5.0-rc2-calico
v2.6.0
v2.6.0-calico
v2.6.0-rc1
v2.6.0-rc1-calico
v2.6.0-rc2
v2.6.0-rc2-calico
v2.6.2
v2.6.2-calico
v3.*
v3.0.0
v3.0.0-alpha1-rc1
v3.0.0-alpha1-rc1-calico
v3.0.0-calico
v3.0.1
v3.0.1-calico
v3.0.12
v3.0.12-calico
v3.1.7
v3.1.7-calico
v3.10.0
v3.10.0-calico
v3.10.2
v3.10.2-calico
v3.11.1
v3.11.1-calico
v3.16.0
v3.16.0-calico
v3.16.5
v3.16.5-calico
v3.17.5
v3.17.5-calico
v3.18.1
v3.18.1-calico
v3.18.5
v3.18.5-calico
v3.2.0
v3.2.0-calico
v3.2.8
v3.2.8-calico
v3.22.3-0.dev
v3.24.0-0.dev
v3.25.0-0.dev
v3.27.0-0.dev
v3.28.0-0.dev
v3.29.0-0.dev
v3.3.7
v3.3.7-calico
v3.30.0-0.dev
v3.31.0-0.dev
v3.31.1
v3.8.5
v3.8.5-calico
v3.9.0
v3.9.0-calico
v3.9.4
v3.9.4-calico

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6540.json"