CVE-2025-64323 - kgateway is missing xDS authorization", "Conte...

CVE-2025-64323 - kgateway is missing xDS authorization", "Conte...

{ "Source": "CVE FEED", "Title": "CVE-2025-64323 - kgateway is missing xDS authorization", "Content": "CVE ID : CVE-2025-64323 Published : Nov. 7, 2025, 4:15 a.m. | 34 minutes ago Description : kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...", "Detection Date": "07 Nov 2025", "Type": "Vulnerability"}🔹 t.me/cvedetector 🔹

CVE Details

Severity
MEDIUM
Published
Nov. 7, 2025
Attack Vector: network