๐Ÿ” CVE Alert

CVE-2026-41186

UNKNOWN 0.0

Unauthenticated Go pprof exposure in Calico debug server

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.

CWE CWE-489 CWE-200
Vendor tigera
Product calico
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for tigera calico

Be the first to know when new unknown vulnerabilities affecting tigera calico are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tigera / Calico
0 < 3.31.6 3.32.0 < 3.32.1
Tigera / Calico Enterprise
0 < 3.21.7 3.22.0 < 3.22.4
Tigera / Calico Cloud
0 < 22.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/projectcalico/calico/pull/12491 github.com: https://github.com/projectcalico/calico/pull/12634 github.com: https://github.com/projectcalico/calico/pull/12633 tigera.io: https://www.tigera.io/security-bulletins/tta-2026-004/

Credits

Behnam Shobiri Behnam Shobiri Anthony Tam Matt Dupre