Description
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.
Published: 2026-07-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Prior to Cilium specific 1.18.x and 1.19.x releases, administrators can create CiliumLocalRedirectPolicies that accept arbitrary ClusterIP addresses via the addressMatcher field. This flaw allows a user with policy‑creation privileges to specify any IP in any namespace, effectively redirecting traffic destined for a Service to an attacker‑controlled endpoint. Deleting such a policy can also corrupt Cilium’s Service. The weaknesses involve unauthorized modification of existing service routing data, reflected by CWE‑863.

Affected Systems

The vulnerability exists in the open‑source networking stack Cilium. Affected releases are all versions prior to 1.17.16, versions 1.18.2 through 1.18.9, and 1.19.0 through 1.19.3. Upgrading to 1.17.16, 1.18.10, or 1.19.4 resolves the issue.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector requires the ability to create or delete CiliumLocalRedirectPolicies, which typically demands cluster‑level privileges. An attacker with such authority can hijack cross‑namespace service traffic or cause denial of service by corrupting service translation.

Generated by OpenCVE AI on July 23, 2026 at 13:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cilium to a fixed version (at least 1.17.16, 1.18.10, or 1.19.4).
  • Restrict the creation of CiliumLocalRedirectPolicies to trusted cluster administrators and enforce namespace‑scope checks.
  • Audit existing policies for arbitrary addressMatcher entries across namespaces and delete or modify those that expose services beyond the intended namespace.

Generated by OpenCVE AI on July 23, 2026 at 13:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q6h5-q3q6-f87x CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
History

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cilium
Cilium cilium
Vendors & Products Cilium
Cilium cilium

Tue, 07 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.
Title CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T13:18:09.946Z

Reserved: 2026-06-11T15:46:12.317Z

Link: CVE-2026-53935

cve-icon Vulnrichment

Updated: 2026-07-08T13:17:54.196Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T13:15:02Z

Weaknesses