kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
History

Fri, 07 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Kgateway
Kgateway kgateway
Vendors & Products Kgateway
Kgateway kgateway

Fri, 07 Nov 2025 03:30:00 +0000

Type Values Removed Values Added
Description kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
Title kgateway is missing xDS authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-07T03:18:48.993Z

Updated: 2025-11-07T17:50:53.540Z

Reserved: 2025-10-30T17:40:52.027Z

Link: CVE-2025-64323

cve-icon Vulnrichment

Updated: 2025-11-07T17:49:53.336Z

cve-icon NVD

Status : Received

Published: 2025-11-07T04:15:47.243

Modified: 2025-11-07T04:15:47.243

Link: CVE-2025-64323

cve-icon Redhat

No data.