CVE-2026-15738
Awaiting Analysis Awaiting Analysis - Queue

Incorrect Behavior Order in AWS Load Balancer Controller Gateway API

Vulnerability report for CVE-2026-15738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: AMZN

Description

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should upgrade to version 3.4.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amazon aws_load_balancer_controller 3.4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before version 3.4.2. An authenticated remote user could exploit this to intercept, spoof, or deny gRPC traffic belonging to another namespace on a shared Gateway by crafting a malicious HTTPRoute resource.

Impact Analysis

If exploited, this vulnerability could allow unauthorized interception or manipulation of gRPC traffic between services. This may lead to data breaches, service disruption, or unauthorized access to sensitive information in shared Gateway environments.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to or manipulation of sensitive data in transit. Organizations using shared Gateways must address this to maintain data protection and privacy standards.

Mitigation Strategies

Upgrade the Amazon AWS Load Balancer Controller to version 3.4.2 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart