CVE-2026-56743

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*

History

17 Jul 2026, 17:29

Type Values Removed Values Added
First Time Cilium
Cilium cilium
References () https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8 - () https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8 - Patch
References () https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171 - () https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171 - Patch
References () https://github.com/cilium/cilium/pull/46305 - () https://github.com/cilium/cilium/pull/46305 - Patch
References () https://github.com/cilium/cilium/pull/46456 - () https://github.com/cilium/cilium/pull/46456 - Patch
References () https://github.com/cilium/cilium/releases/tag/v1.19.5 - () https://github.com/cilium/cilium/releases/tag/v1.19.5 - Release Notes
References () https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r - () https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r - Vendor Advisory
CPE cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*

15 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 20:17

Updated : 2026-07-17 17:29


NVD link : CVE-2026-56743

Mitre link : CVE-2026-56743

CVE.ORG link : CVE-2026-56743


JSON object : View

Products Affected

cilium

  • cilium
CWE
CWE-863

Incorrect Authorization