github.com/projectcalico/calico
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/projectcalico/calicopage 1 of 1
- CVE-2020-13597MEDIUMCVSS 6.0EG 6.0fixed in 3.14.1, 3.13.4, 3.12.2, 3.11.3, 3.10.4, 3.9.6 or 3.8.9, by version range2020-06-03
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure th…
- CVE-2022-28224MEDIUMCVSS 5.5EG 5.5fixed in 3.22.2, 3.21.5 or 3.20.5, by version range2022-06-06
Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a f…
- CVE-2023-41378HIGHCVSS 7.5EG 7.5fixed in 3.26.32023-11-06
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. …
- CVE-2024-33522MEDIUMCVSS 6.7EG 6.7fixed in 3.26.5 or 3.27.3, by version range2024-04-29
In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges b…
- CVE-2026-41184MEDIUMCVSS 6.5EG 6.5fixed in 3.31.6 or 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f, by version range2026-05-28
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes t…
- CVE-2026-41185MEDIUMCVSS 6.5EG 6.5fixed in 3.31.6 or 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f, by version range2026-05-28
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unm…
Check whether github.com/projectcalico/calico is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/projectcalico/calico CVEs against the assets you own.
Book a Demo →