Database/Container, Kubernetes & orchestration
Cilium: With native routing plus WireGuard node encryption, traffic from pods on other nodes is wrongly permitted
CVSS 6.1CVE-2026-26963Container, Kubernetes & orchestrationcurated
Impact
With native routing plus WireGuard node encryption, traffic from pods on other nodes is wrongly permitted
Who can reach it
Any pod on the cluster network
What to do
Rolling Cilium upgrade
References
Related entries
- Cilium: A namespaced HTTPRoute can mirror another tenant's HTTP trafficCVE-2026-56742 · CiliumMedium
- Cilium: L3 port-range plus L7 allow combination results in over-permissive policyCVE-2024-52529 · CiliumMedium
- Cilium: Ingress NetworkPolicies not enforced for pod traffic to L7 servicesCVE-2026-33726 · CiliumMedium
- Cilium: CIDR ipBlock rules without selectors generate a wildcard, over-permitting trafficCVE-2026-56743 · CiliumMedium
- Cilium: Denial of service in the Cilium dataplaneCVE-2025-23028 · CiliumMedium
- Cilium: Agent pod hostPath allows writing to /opt/cni/bin, replacing the CNI binary on the hostCVE-2023-27593 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.