CVE-2026-53935

MEDIUM

Cilium - Cross-Namespace Service Traffic Hijacking via addressMatcher

Title source: manual
STIX 2.1

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.

Scores

CVSS v3 6.9
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
cilium/cilium < 1.17.16
cilium/cilium >= 1.18.2, < 1.18.10
cilium/cilium >= 1.19.0, < 1.19.4
Published Jul 07, 2026
Tracked Since Jul 08, 2026