Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-41186
Published:July 30, 2026
Updated:August 06, 2026
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.
Affected Packages
https://github.com/projectcalico/calico.git (GITHUB):
Affected version(s) >=v3.31.0 <v3.31.6
Fix Suggestion:
Update to version v3.31.6
https://github.com/projectcalico/calico.git (GITHUB):
Affected version(s) =v3.32.0 <v3.32.1
Fix Suggestion:
Update to version v3.32.1
Do you need more information?
Contact Us
CVSS v4
Base Score:
6
Attack Vector
ADJACENT
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
LOW
Subsequent System Integrity
LOW
Subsequent System Availability
LOW
CVSS v3
Base Score:
7.4
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
Active Debug Code
Exposure of Sensitive Information to an Unauthorized Actor
EPSS
Base Score:
0.23