Application Layer Policy Vulnerability in Calico by Tigera
CVE-2026-6540
7.9HIGH
Key Information:
- Vendor
Tigera
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2026-6540?
A vulnerability exists in Calico's Application Layer Policy (which is disabled by default), wherein it fails to effectively normalize URL paths due to improper handling of path-traversal segments, encoded slashes, and repeated slashes. This flaw allows HTTP requests to bypass intended restrictions, as Dikastes mistakenly permits requests under specific prefixes. An attacker on the network, lacking special RBAC permissions, could exploit this vulnerability to access restricted HTTP endpoints that should be protected by the policy.
Affected Version(s)
Calico 0 < 3.31.6
Calico Cloud 0 < 22.4.0
Calico Enterprise 0 < 3.21.7
References
CVSS V4
Score:
7.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Behnam Shobiri
Seth Malaki
Anthony Tam
Matt Dupre
