CVE-2026-6720High▾ TwilightCalico Inserts Sensitive Information into Log File
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Kubernetes API bearer token, etcd password, and inline PEM-encoded etcd client certificate and key. Any reader of that stderr stream — CI job logs, session-recording archives, shared support-ticket transcripts, or local filesystem viewers on the host that ran calicoctl — can extract these credentials with zero Kubernetes privilege. calicoctl's default log level is panic, so this issue only triggers when verbose logging is explicitly enabled.
github.com/projectcalico/calicoctl/v3 < 3.31.6Upgrade to a patched release:
github.com/projectcalico/calicoctl/v3 3.31.6Connected by shared product, vendor, weakness, or advisory.
CVE-2024-33522Medium· 6.7Calico privilege escalation vulnerability
CVE-2020-13597Medium· 6.0Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
CVE-2022-28224Medium· 5.5Calico vulnerable to pod route hijacking
CVE-2023-41378High· 7.5Calico Typha denial of service vulnerability