Description
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
Published: 2026-07-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cilium, a networking and security platform, has a flaw (CWE‑862: Privilege Escalation – Missing Authorization) where users with permission to create or update namespaced HTTPRoutes can configure those routes to point to any Service in any namespace. The vulnerability bypasses the ReferenceGrant authorization mechanism that is meant to restrict cross‑namespace traffic. As a result, an attacker could redirect legitimate HTTP traffic to a malicious service in another namespace, potentially exposing sensitive data or facilitating lateral movement.

Affected Systems

The issue affects Cilium clusters running versions prior to 1.17.17, 1.18.11, or 1.19.5 that have the Gateway API enabled. Gateway API functionality is disabled by default, but if it has been enabled, the affected releases are vulnerable.

Risk and Exploitability

The CVSS score is 5.9, indicating moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation, and it is not listed in CISA’s KEV catalog. However, the flaw can be exploited by an authenticated user with permissions to create or edit HTTPRoutes; thus organizations using gateway functionality or with permissive RBAC should consider the risk significant enough to apply the fix promptly.

Generated by OpenCVE AI on July 31, 2026 at 03:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cilium to version 1.17.17, 1.18.11, or 1.19.5 or later; all releases after these have this issue fixed.
  • If Gateway API is not required, disable the Gateway API feature to eliminate the attack surface.
  • Review RBAC policies so that only trusted users can create or update HTTPRoutes, and enforce the use of ReferenceGrant to restrict cross‑namespace traffic.

Generated by OpenCVE AI on July 31, 2026 at 03:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Cilium
Cilium cilium
Vendors & Products Cilium
Cilium cilium

Wed, 15 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
Title Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-16T12:57:08.040Z

Reserved: 2026-06-22T19:17:28.959Z

Link: CVE-2026-56742

cve-icon Vulnrichment

Updated: 2026-07-16T12:56:50.559Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:15:04Z

Weaknesses