CVE-2026-6540
L7 policy bypass via unnormalized HTTP path matching
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.
| CWE | CWE-22 CWE-23 |
| Vendor | tigera |
| Product | calico |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for tigera calico
Be the first to know when new unknown vulnerabilities affecting tigera calico are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Tigera / Calico
0 < 3.31.6
Tigera / Calico Enterprise
0 < 3.21.7 3.22.0 < 3.22.4
Tigera / Calico Cloud
0 < 22.4.0
References
Credits
Behnam Shobiri Seth Malaki Anthony Tam Matt Dupre