CVE-2026-56742
גבוהה 8.9
תיאור (מקור, אנגלית)
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
מדדים
- CVSS 3.1
-
8.9 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-8/8/2026
- CWE
- CWE-862
מוצרים מושפעים
cilium: cilium
קישורים
- https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj Vendor Advisory
- https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb Patch
- https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857 Patch
- https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b Patch
- https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca Patch
- https://github.com/cilium/cilium/releases/tag/v1.17.17 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.18.11 Release Notes
- https://github.com/cilium/cilium/releases/tag/v1.19.5 Release Notes