CVE-2026-15738: Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource.
To mitigate this issue, users should upgrade to version 3.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon AWS Load Balancer Controllerto a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15738?
CVE-2026-15738 has a severity rating of medium with a score of 5.8.
How do I fix CVE-2026-15738?
To mitigate CVE-2026-15738, upgrade the Amazon AWS Load Balancer Controller to version 3.4.2 or later.
What type of attacks can be executed due to CVE-2026-15738?
CVE-2026-15738 allows an authenticated remote user to intercept, spoof, or deny gRPC traffic on a shared Gateway.
Which software is affected by CVE-2026-15738?
The affected software for CVE-2026-15738 is Amazon AWS Load Balancer Controller before version 3.4.2.
When was CVE-2026-15738 published?
CVE-2026-15738 was published on July 14, 2026.