PT-2026-66493 · Tigera+1 · Calico+2

·

CVE-2026-6540

·

Published

2026-07-30

·

Updated

2026-08-08

CVSS v4.0

7.9

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Calico (affected versions not specified)
Description The Application Layer Policy, which uses Dikastes to enforce HTTP rules, does not perform URL path normalization. This allows HTTP requests containing repeated slashes, encoded slashes, or path-traversal segments to bypass Prefix path rules. While Dikastes authorizes the request based on the permitted prefix, a fronting proxy or the downstream workload normalizes the path, granting an attacker with network access to restricted HTTP endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6540

Affected Products

Calico
Calico Cloud
Calico Enterprise