mediumCVE-2026-56742

CVE-2026-56742 cilium vulnerability

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.

Browse Network Security security risks
Productcilium
CVSS5.9
EPSS0.00171
UpdatedJuly 19, 2026

Quick answer

cilium should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.

Who is affected

Affected versions

  • < 1.17.17
  • >= 1.18.0, < 1.18.11
  • >= 1.19.0, < 1.19.5

Fixed versions

  • 1.17.17
  • 1.18.11
  • 1.19.5

How to fix it

Cilium is affected by CVE-2026-56742, a Gateway API authorization bypass for cross-namespace request mirroring. A user who can create an HTTPRoute can mirror traffic to a Service in another namespace without the required ReferenceGrant. Upgrade Cilium to 1.17.17, 1.18.11, 1.19.5, or a later supported patched version for the installed branch. Prioritize exposed production systems and accounts that can reach the affected feature.

  1. Inventory every Cilium deployment, version, exposed endpoint, environment, and owner.
  2. Check clusters with Gateway API enabled and users who can create or update namespaced HTTPRoutes with RequestMirror filters.
  3. Upgrade Cilium to 1.17.17, 1.18.11, 1.19.5, or a later supported patched version for the installed branch.
  4. There is no functional vendor workaround; if patching must wait, restrict HTTPRoute create and update RBAC to cluster administrators.
  5. Audit HTTPRoutes, RequestMirror filters, cross-namespace Services, ReferenceGrants, RBAC changes, and unexpected mirrored traffic.
  6. Remove unauthorized routes, investigate exposed mirrored data, and rotate credentials if copied traffic contained sensitive headers or tokens.
  7. Restart or redeploy affected services when required, remove temporary artifacts, and keep compensating controls until validation is complete.

Scan now. Google sign-in is only needed to unlock fix guidance.

Verify the fix

  • Confirm every Cilium deployment is on 1.17.17, 1.18.11, 1.19.5, or a later supported patched release for its branch; RBAC restriction alone is only a temporary control.
  • Confirm a cross-namespace mirror sends no traffic without a valid ReferenceGrant and works only after the grant is created.
  • Confirm Cilium RBAC, network policy, Gateway API objects, node access, and local socket permissions match the cluster's approved security baseline.
  • Review logs after remediation for continued exploit attempts or signs that the issue was used before the fix.
  • Rerun the relevant dependency, platform, vendor, or Fixnx security check and document the result, affected assets, change record, and cleanup evidence for CVE-2026-56742.

Related categories

Related security risks

More published guidance from the same primary category.

Trusted references

FAQ

What is affected by CVE-2026-56742?

cilium versions listed as affected should be reviewed: < 1.17.17, >= 1.18.0, < 1.18.11, >= 1.19.0, < 1.19.5.

What should I fix first?

Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.

How do I confirm the fix worked?

Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.

How are Fixnx security risk categories chosen?

Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.