Application Layer Policy Vulnerability in Calico by Tigera
CVE-2026-6540

7.9HIGH

Key Information:

Vendor

Tigera

Vendor
CVE Published:
30 July 2026

What is CVE-2026-6540?

A vulnerability exists in Calico's Application Layer Policy (which is disabled by default), wherein it fails to effectively normalize URL paths due to improper handling of path-traversal segments, encoded slashes, and repeated slashes. This flaw allows HTTP requests to bypass intended restrictions, as Dikastes mistakenly permits requests under specific prefixes. An attacker on the network, lacking special RBAC permissions, could exploit this vulnerability to access restricted HTTP endpoints that should be protected by the policy.

Affected Version(s)

Calico 0 < 3.31.6

Calico Cloud 0 < 22.4.0

Calico Enterprise 0 < 3.21.7

References

CVSS V4

Score:
7.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Behnam Shobiri
Seth Malaki
Anthony Tam
Matt Dupre
.