CVE-2026-33726
Last modified
CVE-2026-33726 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. Per-Endpoint Routing is disabled by default, but is automatically enabled in deployments using cloud IPAM, including Cilium ENI on EKS (`eni.enabled`), AlibabaCloud ENI (`alibabacloud.enabled`), Azure IPAM (`azure.enabled`, but not AKS BYOCNI), and some GKE deployments (`gke.enabled`; managed offerings such as GKE Dataplane V2 may use different defaults). It is typically not enabled in tunneled deployments, and chaining deployments are not affected. In practice, Amazon EKS with Cilium ENI mode is likely the most common affected environment. Versions 1.17.14, 1.18.8, and 1.19.2 contain a patch. There is currently no officially verified or comprehensive workaround for this issue. The only option would be to disable per-endpoint routes, but this will likely cause disruptions to ongoing connections, and potential conflicts if running in cloud providers.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cilium | Cilium | < 1.17.14 |
| Cilium | Cilium | >= 1.18.0, < 1.18.8 |
| Cilium | Cilium | >= 1.19.0, < 1.19.2 |
References
- https://docs.cilium.io/en/stable/network/concepts/routing/#routingTechnical Description
- https://docs.cilium.io/en/stable/network/kubernetes/policy/#network-policyTechnical Description
- https://docs.cilium.io/en/stable/network/servicemesh/l7-traffic-managementTechnical Description
- https://docs.cilium.io/en/stable/operations/performance/tuning/#ebpf-host-routingTechnical Description
- https://github.com/cilium/cilium/pull/44693Issue Tracking, Patch
- https://github.com/cilium/cilium/security/advisories/GHSA-hxv8-4j4r-cqgvPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33726?
How severe is CVE-2026-33726?
How do I fix CVE-2026-33726?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33720n8n is an open source workflow automation platform. Prior to…4.2
- CVE-2026-33721MapServer is a system for developing web-based GIS applicati…7.5
- CVE-2026-33722n8n is an open source workflow automation platform. Prior to…5.3
- CVE-2026-33723WWBN AVideo is an open source video platform. In versions up…6.5
- CVE-2026-33724n8n is an open source workflow automation platform. Prior to…7.4
- CVE-2026-33725Metabase is an open source business intelligence and embedde…7.2
- CVE-2026-33727Pi-hole is a Linux network-level advertisement and Internet …6.7
- CVE-2026-33728dd-trace-java is a Datadog APM client for Java. In versions …9.8
- CVE-2026-33729OpenFGA is a high-performance and flexible authorization/per…9.8
- CVE-2026-33730Open Source Point of Sale (opensourcepos) is a web based poi…6.5
- CVE-2026-33731WWBN AVideo is an open source video platform. In versions pr…6.5
- CVE-2026-33732srvx is a universal server based on web standards. Prior to …6.5
Are you affected by CVE-2026-33726?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
