CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering
Bulletin ID: 2026-055-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:30 PM PDT Description: The AWS Load Balancer Controller is an open-source Kubernetes controller that manages AWS Elastic Load Balancing resources for Kubernetes clusters. We identified CVE-2026-15738, an incorrect rule precedence ordering issue in the Gateway API listener rule generation logic. When both an HTTPRoute and a GRPCRoute are attached to the same Application Load Balancer (ALB) HTTPS listener with the same hostname, the controller assigns ALB listener rule priorities based on route kind rather than route specificity. This causes all HTTPRoute-derived rules to receive lower ALB priority numbers, evaluated first by the ALB, than GRPCRoute-derived rules, regardless of which route is more specific. A namespace-scoped user with permission to create HTTPRoute objects in a namespace admitted by a shared Gateway can create a catch-all HTTPRoute that intercepts traffic intended for a more-specific GRPCRoute in another namespace. Impacted versions: AWS Load Balancer Controller v3.4.1 and any version that includes support for attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AI Analysis
Technical Summary
The AWS Load Balancer Controller has a rule precedence ordering flaw in its Gateway API listener rule generation logic. When HTTPRoute and GRPCRoute objects are attached to the same Application Load Balancer HTTPS listener with the same hostname, the controller assigns listener rule priorities based on route kind rather than route specificity. Consequently, HTTPRoute-derived rules receive lower priority numbers and are evaluated first, enabling a catch-all HTTPRoute in one namespace to intercept traffic meant for a more specific GRPCRoute in another namespace. This affects AWS Load Balancer Controller version 3.4.1 and any version that supports attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794). The issue is resolved in version 3.4.2.
Potential Impact
A namespace-scoped user with permission to create HTTPRoute objects can create a catch-all HTTPRoute that intercepts traffic intended for more specific GRPCRoutes in other namespaces sharing the same Gateway. This can lead to unauthorized cross-namespace traffic interception and potential disruption or manipulation of service routing within Kubernetes clusters using the AWS Load Balancer Controller.
Mitigation Recommendations
An official fix is available in AWS Load Balancer Controller version 3.4.2. It is recommended to upgrade to this version or later. As a workaround, restrict the Gateway listener AllowedRoutes.Namespaces.From field to 'Same' or configure a restrictive namespace Selector to limit which namespaces can attach routes to the shared Gateway, preventing untrusted namespaces from creating HTTPRoute objects that interfere with GRPCRoute rules in other namespaces.
CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering
Description
Bulletin ID: 2026-055-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:30 PM PDT Description: The AWS Load Balancer Controller is an open-source Kubernetes controller that manages AWS Elastic Load Balancing resources for Kubernetes clusters. We identified CVE-2026-15738, an incorrect rule precedence ordering issue in the Gateway API listener rule generation logic. When both an HTTPRoute and a GRPCRoute are attached to the same Application Load Balancer (ALB) HTTPS listener with the same hostname, the controller assigns ALB listener rule priorities based on route kind rather than route specificity. This causes all HTTPRoute-derived rules to receive lower ALB priority numbers, evaluated first by the ALB, than GRPCRoute-derived rules, regardless of which route is more specific. A namespace-scoped user with permission to create HTTPRoute objects in a namespace admitted by a shared Gateway can create a catch-all HTTPRoute that intercepts traffic intended for a more-specific GRPCRoute in another namespace. Impacted versions: AWS Load Balancer Controller v3.4.1 and any version that includes support for attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected software
pkg:github/aws/aws-load-balancer-controllerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The AWS Load Balancer Controller has a rule precedence ordering flaw in its Gateway API listener rule generation logic. When HTTPRoute and GRPCRoute objects are attached to the same Application Load Balancer HTTPS listener with the same hostname, the controller assigns listener rule priorities based on route kind rather than route specificity. Consequently, HTTPRoute-derived rules receive lower priority numbers and are evaluated first, enabling a catch-all HTTPRoute in one namespace to intercept traffic meant for a more specific GRPCRoute in another namespace. This affects AWS Load Balancer Controller version 3.4.1 and any version that supports attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794). The issue is resolved in version 3.4.2.
Potential Impact
A namespace-scoped user with permission to create HTTPRoute objects can create a catch-all HTTPRoute that intercepts traffic intended for more specific GRPCRoutes in other namespaces sharing the same Gateway. This can lead to unauthorized cross-namespace traffic interception and potential disruption or manipulation of service routing within Kubernetes clusters using the AWS Load Balancer Controller.
Mitigation Recommendations
An official fix is available in AWS Load Balancer Controller version 3.4.2. It is recommended to upgrade to this version or later. As a workaround, restrict the Gateway listener AllowedRoutes.Namespaces.From field to 'Same' or configure a restrictive namespace Selector to limit which namespaces can attach routes to the shared Gateway, preventing untrusted namespaces from creating HTTPRoute objects that interfere with GRPCRoute rules in other namespaces.
Technical Details
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-055-aws/","fetched":true,"fetchedAt":"2026-07-14T20:30:34.134Z","wordCount":303}
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a569c6a68715ace4326b7fe
Added to database: 07/14/2026, 20:30:34 UTC
Last enriched: 08/08/2026, 17:30:22 UTC
Last updated: 08/27/2026, 00:22:07 UTC
Views: 335
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.