Unauthenticated Go pprof exposure in Calico debug server
Summary
| CVE | CVE-2026-41186 |
|---|---|
| State | PUBLISHED |
| Assigner | Tigera |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-30 15:16:31 UTC |
| Updated | 2026-07-30 17:16:31 UTC |
| Description | When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002340000 probability, percentile 0.144880000 (date 2026-07-31)
Problem Types: CWE-200 | CWE-489 | CWE-489 CWE-489 Active Debug Code | CWE-200 CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
LowSub Integrity
LowSub Availability
LowCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Tigera | Calico | affected 3.31.6 semver | Not specified |
| CNA | Tigera | Calico | affected 3.32.0 3.32.1 semver | Not specified |
| CNA | Tigera | Calico Enterprise | affected 3.21.7 semver | Not specified |
| CNA | Tigera | Calico Enterprise | affected 3.22.0 3.22.4 semver | Not specified |
| CNA | Tigera | Calico Cloud | affected 22.4.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/projectcalico/calico/pull/12491 | [email protected] | github.com | |
| github.com/projectcalico/calico/pull/12633 | [email protected] | github.com | |
| github.com/projectcalico/calico/pull/12634 | [email protected] | github.com | |
| www.tigera.io/security-bulletins/tta-2026-004 | [email protected] | www.tigera.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Behnam Shobiri (en)
CNA: Behnam Shobiri (en)
CNA: Anthony Tam (en)
CNA: Matt Dupre (en)
There are currently no legacy QID mappings associated with this CVE.