MEDIUM 5.4 GitHub
CVE-2026-56743
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
### Impact
Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations.
When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `"any"` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label select
Affected Products
- go/github.com/cilium/cilium >= 1.19.0, < 1.19.5
References
- https://github.com/advisories/GHSA-fm8w-2m5w-9j7r
- https://github.com/cilium/cilium/security/advisories/GHSA-fm8w-2m5w-9j7r
- https://nvd.nist.gov/vuln/detail/CVE-2026-56743
- https://github.com/cilium/cilium/pull/46305
This medium severity vulnerability with a CVSS score of 5.4 was published on 2026-09-03 via GitHub. Affected: go/github.com/cilium/cilium >= 1.19.0, < 1.19.5.
vulnfeed aggregates 7617 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.