kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kgateway
Kgateway kgateway |
|
| Vendors & Products |
Kgateway
Kgateway kgateway |
Fri, 07 Nov 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0. | |
| Title | kgateway is missing xDS authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-07T03:18:48.993Z
Updated: 2025-11-07T17:50:53.540Z
Reserved: 2025-10-30T17:40:52.027Z
Link: CVE-2025-64323
Updated: 2025-11-07T17:49:53.336Z
Status : Received
Published: 2025-11-07T04:15:47.243
Modified: 2025-11-07T04:15:47.243
Link: CVE-2025-64323
No data.