Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
References
| Link | Resource |
|---|---|
| https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885 | Patch |
| https://github.com/cilium/cilium/pull/42892 | Issue Tracking |
| https://github.com/cilium/cilium/releases/tag/v1.18.6 | Release Notes |
| https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3 | Patch Vendor Advisory |
Configurations
History
20 Feb 2026, 20:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Cilium
Cilium cilium |
|
| References | () https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885 - Patch | |
| References | () https://github.com/cilium/cilium/pull/42892 - Issue Tracking | |
| References | () https://github.com/cilium/cilium/releases/tag/v1.18.6 - Release Notes | |
| References | () https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3 - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:* |
20 Feb 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 00:16
Updated : 2026-02-20 20:12
NVD link : CVE-2026-26963
Mitre link : CVE-2026-26963
CVE.ORG link : CVE-2026-26963
JSON object : View
Products Affected
cilium
- cilium
CWE
CWE-863
Incorrect Authorization
