CVE-2026-53935
### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
Properties
- severity
- medium
- summary
- CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
- epss_score
- 0.00211
- cvss_score
- 6.9
- ghsa_published
- 2026-07-06T20:45:38Z
- source_url
- https://github.com/advisories/GHSA-q6h5-q3q6-f87x
- ghsa_updated
- 2026-07-06T20:45:39Z
- ghsa_id
- GHSA-q6h5-q3q6-f87x
- cve_id
- CVE-2026-53935
- cvss_vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.11621
Related Entities (5)
ENRICHED_BY (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph