GPU VulnDB

Database/Container, Kubernetes & orchestration

Calico: Application Layer Policy (Dikastes) does not normalise URL paths, so path-traversal and encoded

CVE-2026-6540Container, Kubernetes & orchestrationcurated

Impact

Application Layer Policy (Dikastes) does not normalise URL paths, so path-traversal and encoded slashes bypass HTTP rules

Who can reach it

Unauthenticated network reaching a policy-protected service

What to do

Rolling Calico upgrade; do not rely on ALP HTTP rules as the only authorization

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.