Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Seth Malaki

#33836of 56,333
7.9Total CVSS
Vulnerabilities · 1
PT-2026-66493
7.9
2026-07-30
Tigera · Calico · CVE-2026-6540
**Name of the Vulnerable Software and Affected Versions** Calico (affected versions not specified) **Description** The Application Layer Policy, which uses Dikastes to enforce HTTP rules, does not perform URL path normalization. This allows HTTP requests containing repeated slashes, encoded slashes, or path-traversal segments to bypass Prefix path rules. While Dikastes authorizes the request based on the permitted prefix, a fronting proxy or the downstream workload normalizes the path, granting an attacker with network access to restricted HTTP endpoints. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.