AWS Load Balancer Controller: Cross-Namespace Traffic Interception Vulnerability (CVE-2026-15738)
AWS Load Balancer Controller versions 3.4.1+ have a rule priority ordering bug that lets namespace-scoped users intercept traffic across namespaces. When HTTPRoute and GRPCRoute share an ALB HTTPS listener with the same hostname, the controller prioritizes HTTPRoute rules first regardless of specificity—allowing attackers to create catch-all HTTPRoutes that hijack traffic meant for more-specific GRPCRoutes. If you're running affected versions with shared Gateways, you need to upgrade immediately to patch this.