---
id: CVE-2026-56743
aliases:
  - GHSA-fm8w-2m5w-9j7r
title: >-
  Cilium may unexpectedly allow ingress traffic from the local namespace when a
  Kubernetes NetworkPolicy is configured with an ipBlock match
summary: >-
  Cilium may unexpectedly allow ingress traffic from the local namespace when a
  Kubernetes NetworkPolicy is configured with an ipBlock match
severity: medium
cvss: 5.4
cwe:
  - CWE-863
vendor: cilium
product: github.com/cilium/cilium
ecosystem: go
affected:
  - 'github.com/cilium/cilium >= 1.19.0, < 1.19.5'
patched:
  - github.com/cilium/cilium 1.19.5
published: '2026-09-03'
updated: '2026-09-03'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-fm8w-2m5w-9j7r'
references:
  - url: 'https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56743'
  - url: 'https://github.com/cilium/cilium/pull/46305'
  - url: 'https://github.com/cilium/cilium/pull/46456'
  - url: >-
      https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8
  - url: >-
      https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171
  - url: 'https://github.com/cilium/cilium/releases/tag/v1.19.5'
  - url: 'https://github.com/advisories/GHSA-fm8w-2m5w-9j7r'
tags:
  - ghsa
  - go
epss: 0.00248
epssPercentile: 0.14293
ingestedAt: '2026-09-03T18:06:42.114Z'
---

## Overview

### Impact

Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations.

When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `"any"` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label selector to the policy's allowed Layer 3 rules, which allows traffic from other workloads in the same namespace as the subject of the policy.

Example policy affected by this issue:
```
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: test-server
  namespace: default
spec:
  podSelector:
    matchLabels:
      app: test-server
  policyTypes:
  - Ingress
  ingress:
  - from:
    - ipBlock:
        cidr: 192.0.2.3
```

In affected versions, this policy erroneously allows the `test-server` Pod in the `default` namespace to receive any traffic from other workloads running in the `default` namespace.

### Patches

This issue has been patched in:

- Cilium v1.19.5

Releases below v1.19.0 are not affected.

### This issue affects:

- Cilium v1.19 between v1.19.0 and v1.19.4 inclusive

### Workarounds

Developers can create the equivalent policy using CiliumNetworkPolicy [fromCIDR expressions](https://docs.cilium.io/en/stable/security/policy/layer3/#ip-cidr-based). CiliumNetworkPolicy and CiliumClusterwideNetworkPolicy are not affected by this issue.

### Acknowledgements

Special thanks to @TheBeeZee for reporting this issue and preparing the fix, and to @fristonio and @odinuge for their assistance in reviewing the solution.

### For more information

If a vulnerability affecting Cilium appears to have been found, the Cilium security team strongly encourages reporting it to the security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and the report will be treated as top priority.

## Affected packages

- `github.com/cilium/cilium >= 1.19.0, < 1.19.5`

## Remediation

Upgrade to a patched release:

- `github.com/cilium/cilium 1.19.5`
