← Back

CVE-2026-56742

nvd nist
Published: Jul 15, 2026Modified: Jul 17, 2026

JSON object

Loading...
8.9
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Exploitability: 2.3 / Impact: 6.0
Source: NVD

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.

Affected (3)

Products: Cilium: Cilium
1 product
Cilium
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cilium
Before 1.17.17
From 1.18.0 to 1.18.11
From 1.19.0 to 1.19.5

References (8)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.