VYPR
Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller

CVE-2026-15738

Description

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource.

To mitigate this issue, users should upgrade to version 3.4.2.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.