PT-2026-66493 · Tigera+1 · Calico+2
CVSS v4.0
7.9
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
Calico (affected versions not specified)
Description
The Application Layer Policy, which uses Dikastes to enforce HTTP rules, does not perform URL path normalization. This allows HTTP requests containing repeated slashes, encoded slashes, or path-traversal segments to bypass Prefix path rules. While Dikastes authorizes the request based on the permitted prefix, a fronting proxy or the downstream workload normalizes the path, granting an attacker with network access to restricted HTTP endpoints.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Calico
Calico Cloud
Calico Enterprise