Vulnerability Description
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should upgrade to version 3.4.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-055-aws/
- https://github.com/kubernetes-sigs/aws-load-balancer-controller/releases/tag/v3.
FAQ
What is CVE-2026-15738?
CVE-2026-15738 is a vulnerability with a CVSS score of 8.5 (HIGH). Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another n...
How severe is CVE-2026-15738?
CVE-2026-15738 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15738?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.