CVE-2025-64323 - CVE House
Back to Database
Status published Medium CVE-2025-64323

kgateway is missing xDS authorization

Vulnerability Description

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64323

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

kgateway-dev

View all reports →

Affected Software

kgateway
Vulnerable Versions:
>= 2.1.0-agw-cel-rbac, < 2.1.0, < 2.0.5

Timeline

Official Publish: November 7th, 2025
Last Modified: November 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)