8.9

CVE-2026-56742

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiliumCilium Version < 1.17.17
CiliumCilium Version >= 1.18.0 < 1.18.11
CiliumCilium Version >= 1.19.0 < 1.19.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.9 2.3 6
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
security-advisories@github.com 5.9 1.7 3.7
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj
Vendor Advisory
https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb
Patch
https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857
Patch
https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b
Patch
https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca
Patch
https://github.com/cilium/cilium/releases/tag/v1.17.17
Release Notes
https://github.com/cilium/cilium/releases/tag/v1.18.11
Release Notes
https://github.com/cilium/cilium/releases/tag/v1.19.5
Release Notes