CVE-2026-6540
Last modified
CVE-2026-6540 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tigera | Calico | < 3.21.7 |
| Tigera | Calico | < 3.31.6 |
| Tigera | Calico | <= 22.4.0 |
| Tigera | Calico | >= 3.22.0, < 3.22.4 |
| Tigera | Calico | >= 3.32.0, < 3.32.1 |
References
- https://github.com/projectcalico/calico/pull/12531Issue Tracking, Patch
- https://github.com/projectcalico/calico/pull/12532Issue Tracking, Patch
- https://github.com/projectcalico/calico/pull/12533Issue Tracking, Patch
- https://www.tigera.io/security-bulletins/tta-2026-005/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-6540?
How severe is CVE-2026-6540?
How do I fix CVE-2026-6540?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-65390An integer overflow was addressed with improved input valida…8.8
- CVE-2026-65391An out-of-bounds write issue was addressed with improved bou…8.8
- CVE-2026-65393A permissions issue was addressed with improved validation. …5.5
- CVE-2026-65395An out-of-bounds write issue was addressed with improved bou…6.5
- CVE-2026-65398An out-of-bounds access issue was addressed with improved bo…7.8
- CVE-2026-65399A file quarantine bypass was addressed with additional check…4.4
- CVE-2026-65400An authentication issue was addressed with improved state ma…9.8
- CVE-2026-65401A race condition was addressed with improved state handling.…5.5
- CVE-2026-65402A use after free issue was addressed with improved memory ma…5.5
- CVE-2026-65403This issue was addressed with improved checks. This issue is…5.5
- CVE-2026-65404An authorization issue was addressed with improved state man…5.5
- CVE-2026-65405A memory initialization issue was addressed with improved me…5.5
Are you affected by CVE-2026-6540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
