CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15738

highCVSS 8.5covered by 2 sourcesfirst seen 2026-07-14
Bulletin ID: 2026-055-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:30 PM PDT Description: The AWS Load Balancer Controller is an open-source Kubernetes controller that manages AWS Elastic Load Balancing resources for Kubernetes clusters. We identified CVE-2026-15738, an incorrect rule precedence ordering issue in the Gateway API listener rule generation logic. When both an HTTPRoute and a GRPCRoute are attached to the same Application Load Balancer (ALB) HTTPS listener with the same hostname, the controller assigns ALB listener rule priorities based on route kind rather than route specificity. This causes all HTTPRoute-derived rules to receive lower ALB priority numbers, evaluated first by the ALB, than GRPCRoute-derived rules, regardless of which route is more specific. A namespace-scoped user with permission to create HTTPRoute objects in a namespace admitted by a shared Gateway can create a catch-all HTTPRoute that intercepts traffic intended for a more-specific GRPCRoute in another namespace. Impacted versions: AWS Load Balancer Controller v3.4.1 and any version that includes support for attaching both HTTPRoute and GRPCRoute to the same listener (introduced in PR #4794) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

What
An issue with rule precedence in the AWS Load Balancer Controller could lead to misconfigured traffic handling.
Who is affected
Users of the AWS Load Balancer Controller managing Kubernetes clusters are affected.
Urgency
This issue is important but not actively exploited, requiring attention but not immediate action.
Action
Users should review and adjust their configurations as necessary.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15738

Get an email if CVE-2026-15738 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-15738

CVE.org record

Embed the live status

CVE-2026-15738 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15738 status](https://www.csirts.com/badge/CVE-2026-15738)](https://www.csirts.com/cve/CVE-2026-15738)