Dismissed
Permalink
CVE-2026-26963
6.1 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): ADJACENT_NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package cilium-cli
- @LeSuisse dismissed
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
References
- https://github.com/cilium/cilium/pull/42892 x_refsource_MISC
- https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885 x_refsource_MISC
- https://github.com/cilium/cilium/releases/tag/v1.18.6 x_refsource_MISC
- https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3 x_refsource_CONFIRM
Affected products
cilium
- ==>= 1.18.0, < 1.18.6