VulnerabilityAnalyzed
CVE-2026-26963
Cilium is a networking, observability, and security solution with an eBPF-based dataplane.
MEDIUM 5.4EPSS 0.13%
Does this matter?
Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- cilium/cilium
- Source
- security-advisories@github.com
References
- https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885Patch
- https://github.com/cilium/cilium/pull/42892Issue Tracking
- https://github.com/cilium/cilium/releases/tag/v1.18.6Release Notes
- https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.