CVE-2026-56742Medium· 5.9▾ SunlitCilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any S…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.3%
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
cilium < 1.17.17cilium >= 1.18.0, < 1.18.11cilium >= 1.19.0, < 1.19.5Upgrade past the affected range:
cilium 1.19.5Affected packages:
github.com/cilium/cilium < 1.17.17github.com/cilium/ciliumCilium >= 1.18.0, < 1.18.11github.com/cilium/cilium >= 1.19.0, < 1.19.5Patched in:
github.com/cilium/cilium 1.17.17github.com/cilium/ciliumCilium 1.18.11github.com/cilium/cilium 1.19.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56743Medium· 5.4Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2022-29178High· 8.8Access to Unix domain socket can lead to privileges escalation in Cilium
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
CVE-2023-28114Medium· 4.8`cilium-cli` disables etcd authorization for clustermesh clusters