CVE-2026-56742

MEDIUM

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

Title source: cna
STIX 2.1

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.

Scores

CVSS v3 5.9
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
cilium/cilium < 1.17.17 (2 CPE variants)
cilium/cilium >= 1.18.0, < 1.18.11
cilium/cilium >= 1.19.0, < 1.19.5
Published Jul 15, 2026
Tracked Since Jul 16, 2026