mediumCVSS 6.9Vulnerability

CVE-2026-53935

### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.

Properties

severity
medium
summary
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
epss_score
0.00211
cvss_score
6.9
ghsa_published
2026-07-06T20:45:38Z
source_url
https://github.com/advisories/GHSA-q6h5-q3q6-f87x
ghsa_updated
2026-07-06T20:45:39Z
ghsa_id
GHSA-q6h5-q3q6-f87x
cve_id
CVE-2026-53935
cvss_vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
is_ghsa_only
false
epss_percentile
0.11621

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]URL Redirection to Untrusted Site ('Open Redirect')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/cilium/cilium

AFFECTS (1)

[Software]go/github.com/cilium/cilium

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-53935 (CVSS 6.9) — Ninja Signal Threat Intelligence | Ninja Signal