Network policy agent: distinguish pod-name and namespace keys
Fixed in: AWS network policy agent v1.3.7 contains PR #563
details
- Finding IDs
- F-AWS-NPA-001
- Status
- fixed publicly
- Fixed in
- AWS network policy agent v1.3.7 contains PR #563
- Recorded credit
- Public fix author: parlakisik. Public 1seal credit and a causal link to our report are not established.
- Note
- Merged 2026-05-21. The patch separates pod name and namespace in GetPodNamespacedName so different objects do not share an ambiguous concatenated key. The earlier local test called the real helper with device operations substituted; it did not demonstrate traffic on a running cluster. This is a matching key correction, not a general network-policy bypass claim. CVE-2026-86831 concerns a different helper and patch and is not assigned to this record.
F-AWS-NPA-001: Input / state handling. Ambiguous pod/namespace keys can associate distinct objects with the same policy-tracking state. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-NPA-001
Security area (1seal assessment): Authorization. Ambiguous pod/namespace keys can associate distinct objects with the same policy-tracking state. Reviewed 7 Oct 2026.