CVE-2026-56743
published 2026-07-15CVE-2026-56743: Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock…
PriorityP425medium5.4CVSS 3.1
AVAACLPRLUINSCCLILAN
EPSS
0.25%
16.4th percentile
Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | >= 1.19.0 < 1.19.5 | 1.19.5 |
| github.com | cilium_cilium | >= 1.19.0 < 1.19.5 | 1.19.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
ghsa·2026-09-03
CVE-2026-56743 [MEDIUM] CWE-863 Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
### Impact
Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations.
When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `"any"` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label selector to the policy's allowed Layer 3 rules, which allows traffic from other workloads in the same namespace as the subject of the policy.
Example policy affected
VulDB
Cilium up to 1.19.3 Parser name resolution
vuldb·2026-07-15·CVSS 5.4
CVE-2026-56743 [MEDIUM] Cilium up to 1.19.3 Parser name resolution
A vulnerability classified as problematic was found in Cilium up to 1.19.3. Affected is an unknown function of the component Parser. Such manipulation leads to incorrectly-resolved name.
This vulnerability is referenced as CVE-2026-56743. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/cilium/cilium/commit/1c84ae3b58a7cd54f7ee355e6c524c82f620eae8https://github.com/cilium/cilium/commit/bacea640404c0805c23515353dc1681c5bf35171https://github.com/cilium/cilium/pull/46305https://github.com/cilium/cilium/pull/46456https://github.com/cilium/cilium/releases/tag/v1.19.5https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r
2026-07-15
Published