CVE Feed

    Dashboard / CVE / CVE-2026-6540

    CVE-2026-6540

    Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

    Published:Jul 30, 2026
    Last Modified:Jul 30, 2026
    EPS:Jul 30, 2026
    EPSS Score:
    CVSS Score:7.9

    Affected Products

    Vendor
    Tigera
    Product
    Calico
    Vendor
    Tigera
    Product
    Calico Cloud
    Vendor
    Tigera
    Product
    Calico Enterprise

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High