kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
References
Configurations
No configuration.
History
07 Nov 2025, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-07 04:15
Updated : 2025-11-12 16:20
NVD link : CVE-2025-64323
Mitre link : CVE-2025-64323
CVE.ORG link : CVE-2025-64323
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
