What is CVE-2026-41186?
CVE-2026-41186 occurs when Calico's shared debug server is enabled (disabled by default), causing the kube-controllers and Goldmane components to bind their Go pprof debug listener to 0.0.0.0 without authentication. This allows any pod with network reachability to retrieve sensitive information such as process heap and goroutine stacks. Users are advised to verify if the debug server is enabled and disable it if not needed.
Azərbaycanca: CVE-2026-41186, Calico-nun defolt olaraq deaktiv olan ortaq debug serveri aktiv edildikdə yaranır. Bu zəiflik, kube-controllers və Goldmane komponentlərinin Go pprof debug listenerini autentifikasiyasız olaraq 0.0.0.0 ünvanına bağlaması səbəbindən şəbəkə əlaqəsi olan hər hansı podun proses yaddaşı (heap) və goroutine stack kimi həssas məlumatları əldə etməsinə imkan verir. İstifadəçilərə debug serverin aktiv olub-olmadığını yoxlamaq və lazımsızsa deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which Calico components are affected by CVE-2026-41186?
CVE-2026-41186 affects the Go pprof debug listener of the kube-controllers and Goldmane components.
What sensitive information can a pod access by exploiting CVE-2026-41186?
Any pod with network reachability can retrieve sensitive information such as process heap and goroutine stacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.