medium

CVE-2026-53935

Go · github.com/cilium/cilium

Summary

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

Severity
medium
CVSS
6.9
EPSS
0.3% (p27)
CWE
CWE-601
Also known as
GHSA-q6h5-q3q6-f87x
Published
2026-07-06
Updated
2026-07-06

Advisory details

Impact

Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.

In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service.

Patches

This issue affects:

This issue has been patched in:

Workarounds

There is no workaround to this issue.

Acknowledgements

The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue.

For more information

If there are any questions or comments about this advisory, please reach out on Slack.

To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.