← לוח פגיעויות

CVE-2026-49445

גבוהה 8.8

תיאור (מקור, אנגלית)

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-8/8/2026
CWE
CWE-732

מוצרים מושפעים

cilium: cilium

קישורים