CVE-2026-6720
Description
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Kubernetes API bearer token, etcd password, and inline PEM-encoded etcd client certificate and key. Any reader of that stderr stream — CI job logs, session-recording archives, shared support-ticket transcripts, or local filesystem viewers on the host that ran calicoctl — can extract these credentials with zero Kubernetes privilege. calicoctl's default log level is panic, so this issue only triggers when verbose logging is explicitly enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/projectcalico/calicoctl/v3Go | < 3.31.6 | 3.31.6 |
Affected products
5(expand)+ 1 more
- (no CPE)
- (no CPE)
- osv-coords2 versionspkg:apk/chainguard/calico-cni-fips-3.31pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 0+ 1 more
- (no CPE)range: < 0
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-3m4q-ggcj-j6m4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6720ghsaADVISORY
- github.com/projectcalico/calico/commit/12908bb48a5bf8cbab5373f4d532509a30cf9b7fghsaWEB
- github.com/projectcalico/calico/commit/8d87eddcb5eb6efc70c09eb0a33d63137359ea70ghsaWEB
- github.com/projectcalico/calico/commit/ce3ab2b39b5841757cbccf7922c895c47827f562ghsaWEB
- github.com/projectcalico/calico/pull/12535nvdWEB
- github.com/projectcalico/calico/pull/12536nvdWEB
- github.com/projectcalico/calico/pull/12537nvdWEB
- www.tigera.io/security-bulletins/tta-2026-003ghsaWEB
- www.tigera.io/security-bulletins/tta-2026-003/nvd
News mentions
0No linked articles in our index yet.