Vulnerability Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cilium | Cilium | >= 1.18.0, < 1.18.6 |
Related Weaknesses (CWE)
References
- https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885Patch
- https://github.com/cilium/cilium/pull/42892Issue Tracking
- https://github.com/cilium/cilium/releases/tag/v1.18.6Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3PatchVendor Advisory
FAQ
What is CVE-2026-26963?
CVE-2026-26963 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, ...
How severe is CVE-2026-26963?
CVE-2026-26963 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26963?
Check the references section above for vendor advisories and patch information. Affected products include: Cilium Cilium.