CVE-2026-56742

Published Jul 15, 2026

Last updated 9 days ago

Overview

Description
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
Source
security-advisories@github.com
NVD status
Analyzed
Products
cilium

Risk scores

CVSS 3.1

Type
Primary
Base score
8.9
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-862

Social media

Hype score
Not currently trending

Configurations