Boletines de Vulnerabilidades

CVE-2026-15738

   
Software afectado AWS
 
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource.



To mitigate this issue, users should upgrade to version 3.4.2.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-15738