VYPR
Medium severity5.4NVD Advisory· Published Jul 15, 2026· Updated Jul 17, 2026

CVE-2026-56743

CVE-2026-56743

Description

Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/cilium/ciliumGo
>= 1.19.0, < 1.19.51.19.5

Affected products

10

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.