HIGHVulnerability

CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-6540
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-07-30T15:16:37.533
last_modified
2026-08-08T01:10:43.697

Related Entities (6)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (3)

[Product]
[Product]
[Product]

HAS_WEAKNESS (2)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
[Weakness]Relative Path Traversal

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-6540 — Ninja Signal Threat Intelligence | Ninja Signal