{"id":"CVE-2022-28224","aliases":["GHSA-9394-xfq9-6qrp"],"url":"https://o3.security/vulnerability/CVE-2022-28224","summary":"Calico and Calico Enterprise may be vulnerable to route hijacking with the floating IP feature","details":"Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficient validation, a privileged attacker may be able to set a floating IP annotation to a pod even if the feature is not enabled. This may allow the attacker to intercept and reroute traffic to their compromised pod.","published":"2022-06-06T17:19:12.810Z","modified":"2026-08-07T11:31:25.284761723Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/projectcalico/calico","fixedVersion":"3.22.2"},{"ecosystem":"Go","name":"github.com/projectcalico/calico","fixedVersion":"3.21.5"},{"ecosystem":"Go","name":"github.com/projectcalico/calico","fixedVersion":"3.20.5"}],"fix":null,"references":[{"type":"WEB","url":"https://www.tigera.io/security-bulletins-tta-2022-001/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28224.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28224"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:25.284761723Z"}}