Vulnerability Description
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/cilium/cilium/commit/81d446395673dc2c684c047c12715caffac1a351
- https://github.com/cilium/cilium/commit/92ca32eda85aa0c7611c28221cc26fa08be17ebc
- https://github.com/cilium/cilium/commit/fe7eb53c7aac9fa7ec610b1975d73fbbb198c66d
- https://github.com/cilium/cilium/pull/45412
- https://github.com/cilium/cilium/pull/45584
- https://github.com/cilium/cilium/pull/45585
- https://github.com/cilium/cilium/security/advisories/GHSA-q6h5-q3q6-f87x
FAQ
What is CVE-2026-53935?
CVE-2026-53935 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can speci...
How severe is CVE-2026-53935?
CVE-2026-53935 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53935?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.