Medium severity6.1NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026
CVE-2026-26963
CVE-2026-26963
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/cilium/ciliumGo | >= 1.18.0, < 1.18.6 | 1.18.6 |
Affected products
8- osv-coords6 versionspkg:bitnami/ciliumpkg:bitnami/cilium-operatorpkg:bitnami/hubble-relaypkg:golang/github.com/cilium/ciliumpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
>= 1.18.0, < 1.18.6+ 5 more
- (no CPE)range: >= 1.18.0, < 1.18.6
- (no CPE)range: >= 1.18.0, < 1.18.6
- (no CPE)range: >= 1.18.0, < 1.18.6
- (no CPE)range: >= 1.18.0, < 1.18.6
- (no CPE)range: < 0.0.20260226T182644-150000.1.149.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885nvdPatchWEB
- github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-5r23-prx4-mqg3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-26963ghsaADVISORY
- github.com/cilium/cilium/pull/42892nvdIssue TrackingWEB
- github.com/cilium/cilium/releases/tag/v1.18.6nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.