Bug 2507532 (CVE-2026-66787) - CVE-2026-66787 lighthouse: Go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
Summary: CVE-2026-66787 lighthouse: Go pprof profiling endpoint enabled unconditionall...
Keywords:
Status: NEW
Alias: CVE-2026-66787
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-27 15:44 UTC by OSIDB Bzimport
Modified: 2026-09-01 18:43 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-27 15:44:45 UTC
There is no validation that advertised IPs in EndpointSlice objects fall within the source cluster's allocated Pod/Service/Globalnet CIDR, nor that they are not link-local, loopback, or the importing cluster's own control-plane addresses. A compromised spoke can create an EndpointSlice with attacker-controlled IP addresses for any service name, causing peer clusters' lighthouse DNS to resolve legitimate service names to malicious endpoints. This enables transparent MITM of cross-cluster service traffic without modifying the target service.

Source: Project Glasswing AI-SAST audit of submariner-io/lighthouse.
Finding ID: FIND-001
Assurance: execution_proven


Note You need to log in before you can comment on or make changes to this bug.