When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod w…
Summary
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://www.tigera.io/security-bulletins/tta-2026-004/
Sources
- NVD DATABASE
Original Links
- https://github.com/projectcalico/calico/pull/12491 Issue Tracking
- https://github.com/projectcalico/calico/pull/12633 Issue Tracking
- https://github.com/projectcalico/calico/pull/12634 Issue Tracking
- https://www.tigera.io/security-bulletins/tta-2026-004/ Vendor Advisory
Timeline
- nvd_ingest NVD