CVE-2026-56743

MEDIUM

Cilium 1.19.0-1.19.4 NetworkPolicy - Same-Namespace Ingress Bypass

Title source: manual
STIX 2.1

Description

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.

Scores

CVSS v3 5.4
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
cilium/cilium 1.19.0 - 1.19.5
cilium/cilium >= 1.19.0, < 1.19.5
Published Jul 15, 2026
Tracked Since Jul 16, 2026