Project Calico is a network policy and security platform for containerized and Kubernetes environments, with its vulnerability profile centered on the core Calico product. The observed disclosures cluster around information-exposure weaknesses, including improper handling of sensitive data in transit and unintended disclosure to unauthorized actors, reflecting the policy-enforcement and network-visibility role the platform plays in container orchestration. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectcalico over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromi | Jun 3, 2020 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectcalico.
Media articles that mention a CVE ID that affects a product developed by Projectcalico — matched by CVE ID, not by vendor name.