A AegiFlow
MEDIUMCVSS 5.4EPSS 0.2%

CVE-2026-56743

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Published
2026-09-03
Modified
2026-09-03
EPSS percentile
16%
Aliases
GHSA-fm8w-2m5w-9j7r
Sources
github-advisory

Summary

### Impact Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations. When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `"any"` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label selector to the policy's allowed Layer 3 rules, which allows traffic from other workloads in the same namespace as the subject of the policy. Example policy affected by this issue: ``` apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: test-server namespace: default spec: podSelector: matchLabels: app: test-server policyTypes: - Ingress ingress: - from: - ipBlock: cidr: 192.0.2.3 ``` In affected versions, this policy erroneously allows the `test-server` Pod in the `default` namespace to receive any traffic from other workloads running in the `default` namespace. ### Patches This issue has been patched in: - Cilium v1.19.5 Releases below v1.19.0 are not affected. ### This issue affects: - Cilium v1.19 between v1.19.0 and v1.19.4 inclusive ### Workarounds Developers can create the equivalent policy using CiliumNetworkPolicy [fromCIDR expressions](https://docs.cilium.io/en/stable/security/policy/layer3/#ip-cidr-based). CiliumNetworkPolicy and CiliumClusterwideNetworkPolicy are not affected by this issue. ### Acknowledgements Special thanks to @TheBeeZee for reporting this issue and preparing the fix, and to @fristonio and @odinuge for their assistance in reviewing the solution. ### For more information If a vulnerability affecting Cilium appears to have been found, the Cilium security team strongly encourages reporting it to the security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and the report will be treated as top priority.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/cilium/cilium1.19.5

Remediation: Upgrade to 1.19.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.