Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITEDPATCHED
cilium · clusternetworkpolicy

Cilium ClusterNetworkPolicy matchExpressions Values Silently Dropped

56% confidence

Description

Cilium's ClusterNetworkPolicy CRD conversion function silently drops 'Values' slices for 'In', 'NotIn', 'Equals', or 'NotEquals' operators in 'matchExpressions', leading to network policy enforcement failures. This allows bypassing security controls in multi-tenant clusters.

Affected Products

VendorProductVersions
ciliumclusternetworkpolicyv1.20.0-pre, v1.20.0

Related News (4 articles)

Tier C
oss-security47d ago
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
→ No new info (linked only)
Tier C
oss-security47d ago
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
→ No new info (linked only)
Tier C
oss-security47d ago
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
→ No new info (linked only)
Tier C
oss-security47d ago
Re: [CVE request] Cilium ClusterNetworkPolicy matchExpressions Values silently dropped — 0-day in v1.20.0-pre releases, no maintainer response in 9 days via GHSA Triage
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
fixed version number or null
PublishedJul 7, 2026
Last enriched47d agov4
Tags
network-policyciliumkubernetes
Trending Score0
Source articles4
Independent1
Info Completeness8/14
Missing: cve_id, epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-49445EXP
Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access
MEDIUMCVE-2026-56743
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
MEDIUMCVE-2026-56742
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
LOWCVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
MEDIUMCVE-2026-53935EXP
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Jul 7, 2026
Actively Exploited
Jul 7, 2026
Exploit Available
Jul 7, 2026
Patch Available
Jul 7, 2026
Discovered by ZDM
Jul 7, 2026
Updated: exploitAvailable, activelyExploited
Jul 7, 2026
Updated: patchAvailable
Jul 8, 2026
Updated: affectedVersions
Jul 8, 2026

Version History

v4
Last enriched 47d ago
v4Tier C47d ago

Updated affected versions to include v1.20.0 and noted that the issue has been fixed in development.

affectedVersions
via oss-security
v3Tier C47d ago

Updated patch availability information indicating that the issue has been fixed as part of development activities.

patchAvailable
via oss-security
v2Tier C47d ago

Marked exploitAvailable and activelyExploited as true based on new information.

exploitAvailableactivelyExploited
via oss-security
v147d ago

Initial creation