Количество 3
Количество 3
CVE-2026-53935
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.
CVE-2026-53935
Cilium is a networking, observability, and security solution. Prior to ...
GHSA-q6h5-q3q6-f87x
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53935 Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4. | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53935 Cilium is a networking, observability, and security solution. Prior to ... | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад | |
GHSA-q6h5-q3q6-f87x CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation | CVSS3: 6.9 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу