MEDIUM 5.9 GitHub

CVE-2026-56742

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

### Impact In Cilium clusters using [Gateway API](https://docs.cilium.io/en/stable/network/servicemesh/gateway-api/gateway-api/), users with permissions to create or update namespaced HTTPRoutes can mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. ### Patches This issue affects: * Cilium v1.19 from v1.19.0 to v1.19.4 inclusive * Cilium v1.18 from v1.18.0 to v1.18.10 inclusive * All ve

Affected Products

References

Published: 2026-09-24 · Source: GitHub · Feed updated: 2026-09-24
This medium severity vulnerability with a CVSS score of 5.9 was published on 2026-09-24 via GitHub. Affected: go/github.com/cilium/cilium < 1.17.17, go/github.com/cilium/ciliumCilium >= 1.18.0, < 1.18.11, go/github.com/cilium/cilium >= 1.19.0, < 1.19.5.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.