Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196343 vulns · 36/41 feeds (7d)
← Back to list
6.9
CVE-2026-53935EXPLOITEDPATCHED
cilium · cilium

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

Description

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.

Affected Products

VendorProductVersions
ciliumcilium< 1.17.16, >= 1.18.2, < 1.18.10, >= 1.19.0, < 1.19.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
gogithub.com/cilium/ciliumGHSA85%

References

  • https://github.com/cilium/cilium/security/advisories/GHSA-q6h5-q3q6-f87x(x_refsource_CONFIRM)
  • https://github.com/cilium/cilium/pull/45412(x_refsource_MISC)
  • https://github.com/cilium/cilium/pull/45584(x_refsource_MISC)
  • https://github.com/cilium/cilium/pull/45585(x_refsource_MISC)
  • https://github.com/cilium/cilium/commit/81d446395673dc2c684c047c12715caffac1a351(x_refsource_MISC)
  • https://github.com/cilium/cilium/commit/92ca32eda85aa0c7611c28221cc26fa08be17ebc(x_refsource_MISC)
  • https://github.com/cilium/cilium/commit/fe7eb53c7aac9fa7ec610b1975d73fbbb198c66d(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB47d ago
CVE-2026-53935 | Cilium up to 1.17.15/1.18.9/1.19.3 CiliumLocalRedirectPolicy addressMatcher redirect
→ No new info (linked only)
CVSS 3.16.9 MEDIUM
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
github.com/cilium/cilium@1.19.4github.com/cilium/cilium@1.18.10github.com/cilium/cilium@1.17.16
CWECWE-863
PublishedJul 6, 2026
Last enriched47d agov2
Tags
GHSA-q6h5-q3q6-f87xgoCVE-2026-53935
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-49445EXP
Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access
MEDIUMCVE-2026-56743
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
CRITICALPRE-CVEEXP
Cilium ClusterNetworkPolicy matchExpressions Values Silently Dropped
MEDIUMCVE-2026-56742
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
LOWCVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 6, 2026
Discovered by ZDM
Jul 6, 2026
Updated: description, affectedVersions, severity, activelyExploited, tags
Jul 7, 2026
Actively Exploited
Jul 8, 2026
Patch Available
Jul 8, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated description with new details, changed affected versions, severity to HIGH, and noted that the exploit is not available.

descriptionaffectedVersionsseverityactivelyExploitedtags
via VulDB
v148d ago

Initial creation