CVE-2026-41186

MEDIUM CVSS 4.0: 6.0 EPSS 0.23%
Updated Jul 30, 2026
Bind
Parameter Value
CVSS 6.0 (MEDIUM)
Type CWE-200 (Information Exposure), CWE-489
Vendor Bind
Public PoC No

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material.

The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0