CVE-2026-49445Critical· 9.2▾ MidnightCilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:
This issue affects both the embedded and standalone Envoy deployment models.
This issue affects:
This issue has been patched in https://github.com/cilium/cilium/pull/44512, included in:
There is no known workaround to this issue.
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to moemen for reporting the issue and 0xch4z for their work on triaging and remediating this issue.
If there are any questions or comments about this advisory, please reach out on [Slack (https://docs.cilium.io/en/latest/community/community/).
If anyone thinks they have found a vulnerability affecting Cilium, it is strongly encouraged to report it to the security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and the report will be treated as a top priority.
github.com/cilium/cilium >= 1.19.0, < 1.19.2github.com/cilium/cilium >= 1.18.0, < 1.18.8github.com/cilium/cilium < 1.17.14Upgrade to a patched release:
github.com/cilium/cilium 1.19.2github.com/cilium/cilium 1.18.8github.com/cilium/cilium 1.17.14Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53935Medium· 6.9CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2022-29178High· 8.8Access to Unix domain socket can lead to privileges escalation in Cilium
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy