Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33726

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 5.4
CVSS3: 4.3
EPSS Низкий

Описание

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. Per-Endpoint Routing is disabled by default, but is automatically enabled in deployments using cloud IPAM, including Cilium ENI on EKS (eni.enabled), AlibabaCloud ENI (alibabacloud.enabled), Azure IPAM (azure.enabled, but not AKS BYOCNI), and some GKE deployments (gke.enabled; managed offerings such as GKE Dataplane V2 may use different defaults). It is typically not enabled in tunneled deployments, and chaining deployments are not affected. In practice, Amazon EKS with Cilium ENI mode is likely the most common affected environment. Versions 1.17.14, 1.18.8, and 1.19.2 contain a patch. There is currently no officially verified or comprehensiv

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Версия до 1.17.14 (исключая)
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Версия от 1.18.0 (включая) до 1.18.8 (исключая)
cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*
Версия от 1.19.0 (включая) до 1.19.2 (исключая)

EPSS

Процентиль: 16%
0.00244
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.4
debian
5 месяцев назад

Cilium is a networking, observability, and security solution with an e ...

CVSS3: 5.4
github
5 месяцев назад

Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic

EPSS

Процентиль: 16%
0.00244
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-284