
☸️ Calico network policy bypass disclosed CVE-2026-6540 affects Calico's optional Application Layer Policy. Improper URL normalization means crafted paths containing traversal segments, encoded slashes or repeated slashes may be authorized under an allowed prefix while reaching a restricted endpoint after normalization. 🔎 Source: Calico / Tenable. #Kubernetes #Calico #CloudSecurity #CVE #CyberSecurity
Post summary
The post announces CVE-2026-6540, detailing a URL normalization bypass in Calico’s policy enforcement, but provides no PoC, exploit, patch, or evidence of active exploitation.
