Dismissed
Permalink
CVE-2026-26963
6.1 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package cilium-cli
- @LeSuisse dismissed
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
References
-
https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3 x_refsource_CONFIRM
-
https://github.com/cilium/cilium/pull/42892 x_refsource_MISC
-
https://github.com/cilium/cilium/releases/tag/v1.18.6 x_refsource_MISC
Affected products
cilium
- ==>= 1.18.0, < 1.18.6
Ignored packages (1)
pkgs.cilium-cli
CLI to install, manage & troubleshoot Kubernetes clusters running Cilium