{"id":"GHSA-q6h5-q3q6-f87x","summary":"CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation","details":"### Impact\n\nUsers with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.\n\nIn addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service.\n\n### Patches\n\nThis issue affects:\n\n- Cilium v1.19.0 to v1.19.3 inclusive  (fixed in PR #45584)\n- Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585)\n- All versions of Cilium prior to v1.17.16 (fixed in PR #45412)\n\nThis issue has been patched in:\n\n- Cilium v1.19.4\n- Cilium v1.18.10\n- Cilium v1.17.16\n\n### Workarounds\n\nThere is no workaround to this issue.\n\n### Acknowledgements\n\nThe Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue.\n\n### For more information\nIf there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/).\n\nTo report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [security@cilium.io](mailto:security@cilium.io). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.","aliases":["BIT-cilium-2026-53935","BIT-cilium-operator-2026-53935","BIT-hubble-relay-2026-53935","CVE-2026-53935","GO-2026-5914"],"modified":"2026-08-24T00:37:06.955033870Z","published":"2026-07-06T20:45:38Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-06T20:45:38Z","nvd_published_at":null,"cwe_ids":["CWE-601"]},"references":[{"type":"WEB","url":"https://github.com/cilium/cilium/security/advisories/GHSA-q6h5-q3q6-f87x"},{"type":"WEB","url":"https://github.com/cilium/cilium/pull/44512"},{"type":"WEB","url":"https://github.com/cilium/cilium/pull/44584"},{"type":"WEB","url":"https://github.com/cilium/cilium/pull/44585"},{"type":"PACKAGE","url":"https://github.com/cilium/cilium"}],"affected":[{"package":{"name":"github.com/cilium/cilium","ecosystem":"Go","purl":"pkg:golang/github.com/cilium/cilium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.19.0"},{"fixed":"1.19.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q6h5-q3q6-f87x/GHSA-q6h5-q3q6-f87x.json"}},{"package":{"name":"github.com/cilium/cilium","ecosystem":"Go","purl":"pkg:golang/github.com/cilium/cilium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.18.2"},{"fixed":"1.18.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q6h5-q3q6-f87x/GHSA-q6h5-q3q6-f87x.json"}},{"package":{"name":"github.com/cilium/cilium","ecosystem":"Go","purl":"pkg:golang/github.com/cilium/cilium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.17.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-q6h5-q3q6-f87x/GHSA-q6h5-q3q6-f87x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H"}]}