Executive brief
Cilium, a networking and security tool for cloud environments, contains a vulnerability in its Gateway API implementation. Users with specific permissions to manage network routes could bypass security controls to mirror network traffic to unauthorized services across different namespaces. This could lead to unauthorized data observation or service interference, though the affected feature is disabled by default.
Technical details
A missing authorization check in Cilium's Gateway API implementation allows for a ReferenceGrant bypass. Specifically, the reconciliation logic failed to verify if cross-namespace backend references for request-mirror HTTP filters were permitted by an existing ReferenceGrant. An attacker with high privileges (ability to create/update HTTPRoutes) can exploit this to mirror traffic to services in other namespaces. The vulnerability is present in Cilium versions prior to 1.17.17, 1.18.11, and 1.19.5. Gateway API functionality must be enabled for a cluster to be vulnerable.
Affected products
- Cilium Cilium < 1.17.17, >= 1.18.0 < 1.18.11, >= 1.19.0 < 1.19.5
Timeline
- 2026-07-15: advisory: NVD publication date
- 2026-07-15: disclosed: GitHub Security Advisory published
References
- https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb
- https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857
- https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b
- https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca
- https://github.com/cilium/cilium/releases/tag/v1.17.17
- https://github.com/cilium/cilium/releases/tag/v1.18.11
- https://github.com/cilium/cilium/releases/tag/v1.19.5