CVE-2026-26963
MEDIUM6.1EPSS 0.01%Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
發布日:2026/2/19修改日:2026/2/23
也稱為:GHSA-5r23-prx4-mqg3BIT-cilium-2026-26963BIT-cilium-operator-2026-26963BIT-hubble-relay-2026-26963GO-2026-4522
描述
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
受影響套件(5)
- Bitnami/cilium>= 1.18.0, < 1.18.6
- Bitnami/cilium-operator>= 1.18.0, < 1.18.6
- Bitnami/hubble-relay>= 1.18.0, < 1.18.6
- Go/github.com/cilium/cilium>= 1.18.0, < 1.18.6
- Go/github.com/cilium/cilium>= 1.18.0, < 1.18.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-26963
- PATCHhttps://github.com/cilium/cilium
- WEBhttps://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885
- WEBhttps://github.com/cilium/cilium/pull/42892
- WEBhttps://github.com/cilium/cilium/releases/tag/v1.18.6
- WEBhttps://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3