Skip to content
AWSCVE-2026-15738

aws-load-balancer-controller: insufficient isolation

Medium5.8CVE-2026-15738 · Published Jul 14, 2026 · updated Jul 15, 2026

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should upgrade to version 3.4.2.

AWS advisory

Affected versions

PackageAffectedFixed in
aws-load-balancer-controller
Product
< 3.4.23.4.2
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-653

More AWS advisories

All AWS
Advisory
Path traversal and arbitrary file write in the workflow linters of...
UnratedJul 17
Issue with Athena Federated Query Synapse Connector
UnratedJul 17
Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
UnratedJul 16
OS command injection in jsii-diff in AWS jsii
UnratedJul 15
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
UnratedJul 15
AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
UnratedJul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.