Vulnerability Description
kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/kgateway-dev/kgateway/issues/10651
- https://github.com/kgateway-dev/kgateway/pull/12471
- https://github.com/kgateway-dev/kgateway/pull/12535
- https://github.com/kgateway-dev/kgateway/security/advisories/GHSA-4766-x535-jw3r
FAQ
What is CVE-2025-64323?
CVE-2025-64323 is a vulnerability with a CVSS score of 5.3 (MEDIUM). kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS p...
How severe is CVE-2025-64323?
CVE-2025-64323 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64323?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.