CVE-2026-56743

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-15 20:17

Updated : 2026-07-17 17:29


NVD link : CVE-2026-56743

Mitre link : CVE-2026-56743

CVE.ORG link : CVE-2026-56743


JSON object : View

Products Affected

cilium

  • cilium
CWE
CWE-863

Incorrect Authorization