Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196343 vulns · 36/41 feeds (7d)
← Back to list
9.2
CVE-2026-49445EXPLOITEDPATCHED
cilium · cilium

Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy admin endpoints, expose TLS secrets, disrupt cluster traffic, or terminate Envoy. This issue is fixed in versions 1.17.14, 1.18.8, and 1.19.2.

Affected Products

VendorProductVersions
ciliumcilium< 1.17.14, >= 1.18.0, < 1.18.8, >= 1.19.0, < 1.19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
gogithub.com/cilium/ciliumGHSA85%

References

  • https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9(x_refsource_CONFIRM)
  • https://github.com/cilium/cilium/pull/44512(x_refsource_MISC)
  • https://github.com/cilium/cilium/commit/7bfbdd5c1be83d6c9ba3e089b4c804b6603505b6(x_refsource_MISC)
  • https://github.com/cilium/cilium/releases/tag/v1.17.14(x_refsource_MISC)
  • https://github.com/cilium/cilium/releases/tag/v1.18.8(x_refsource_MISC)
  • https://github.com/cilium/cilium/releases/tag/v1.19.2(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB39d ago
CVE-2026-49445 | Cilium up to 1.17.13/1.18.7/1.19.1 Admin Endpoints admin.sock improper authentication
→ No new info (linked only)
CVSS 3.19.2 CRITICAL
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
github.com/cilium/cilium@1.19.2github.com/cilium/cilium@1.18.8github.com/cilium/cilium@1.17.14
CWECWE-732
PublishedJul 6, 2026
Last enriched39d agov2
Tags
GHSA-3fcv-jvfp-m4q9go
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-56743
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
CRITICALPRE-CVEEXP
Cilium ClusterNetworkPolicy matchExpressions Values Silently Dropped
MEDIUMCVE-2026-56742
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
LOWCVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
MEDIUMCVE-2026-53935EXP
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 6, 2026
Discovered by ZDM
Jul 6, 2026
Updated: affectedVersions, severity, cvssEstimate, activelyExploited
Jul 15, 2026
Actively Exploited
Jul 16, 2026
Patch Available
Jul 16, 2026

Version History

v2
Last enriched 39d ago
v2Tier C39d ago

Updated affected versions to include < 1.17.13, < 1.18.7, < 1.19.1, changed severity to HIGH, and updated CVSS estimate to 7.0.

affectedVersionsseveritycvssEstimateactivelyExploited
via VulDB
v148d ago

Initial creation