CVE-2023-41378High· 7.5▾ TwilightCalico Typha denial of service vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed inside the main server handle for loop without any timeout allowing an unclean TLS handshake to block the main loop indefinitely while other connections will be idle waiting for that handshake to finish.
github.com/projectcalico/calico >= 3.26.0, < 3.26.3github.com/projectcalico/calico <= 3.25.1Upgrade to a patched release:
github.com/projectcalico/calico 3.26.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-33522Medium· 6.7Calico privilege escalation vulnerability
CVE-2020-13597Medium· 6.0Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
CVE-2022-28224Medium· 5.5Calico vulnerable to pod route hijacking
CVE-2026-6720HighCalico Inserts Sensitive Information into Log File