kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4766-x535-jw3r kgateway is missing xDS authorization
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 03:30:00 +0000

Type Values Removed Values Added
Description kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.
Title kgateway is missing xDS authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-07T03:18:48.993Z

Reserved: 2025-10-30T17:40:52.027Z

Link: CVE-2025-64323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T04:15:47.243

Modified: 2025-11-07T04:15:47.243

Link: CVE-2025-64323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.