Untriaged
Permalink
CVE-2026-26963
6.1 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): ADJACENT_NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
References
-
https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3 x_refsource_CONFIRM
-
https://github.com/cilium/cilium/pull/42892 x_refsource_MISC
-
https://github.com/cilium/cilium/releases/tag/v1.18.6 x_refsource_MISC
Affected products
cilium
- ==>= 1.18.0, < 1.18.6
Package maintainers
-
@akshatagarwl Akshat Agarwal <humancalico@disroot.org>
-
@qjoly Quentin JOLY <github@une-pause-cafe.fr>
-
@bryanasdev000 Bryan Albuquerque <bryanasdev000@gmail.com>
-
@ryan4yin Ryan Yin <xiaoyin_c@qq.com>