CVE-2026-53935Medium· 6.9▾ SunlitCiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.
In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service.
This issue affects:
This issue has been patched in:
There is no workaround to this issue.
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue.
If there are any questions or comments about this advisory, please reach out on Slack.
To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
github.com/cilium/cilium >= 1.19.0, < 1.19.4github.com/cilium/cilium >= 1.18.2, < 1.18.10github.com/cilium/cilium < 1.17.16Upgrade to a patched release:
github.com/cilium/cilium 1.19.4github.com/cilium/cilium 1.18.10github.com/cilium/cilium 1.17.16Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2022-29178High· 8.8Access to Unix domain socket can lead to privileges escalation in Cilium
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy