CVE-2026-33726 Details
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. Per-Endpoint Routing is disabled by default, but is automatically enabled in deployments using cloud IPAM, including Cilium ENI on EKS (`eni.enabled`), AlibabaCloud ENI (`alibabacloud.enabled`), Azure IPAM (`azure.enabled`, but not AKS BYOCNI), and some GKE deployments (`gke.enabled`; managed offerings such as GKE Dataplane V2 may use different defaults). It is typically not enabled in tunneled deployments, and chaining deployments are not affected. In practice, Amazon EKS with Cilium ENI mode is likely the most common affected environment. Versions 1.17.14, 1.18.8, and 1.19.2 contain a patch. There is currently no officially verified or comprehensive workaround for this issue. The only option would be to disable per-endpoint routes, but this will likely cause disruptions to ongoing connections, and potential conflicts if running in cloud providers.
A vulnerability exists in Cilium's handling of Ingress Network Policies for Layer 7 Services, such as Envoy and GAMMA, with a local backend on the same node. This issue affects Cilium versions prior to 1.17.14, 1.18.0 through 1.18.7, and 1.19.0 through 1.19.1. The vulnerability arises when Per-Endpoint Routing is enabled and BPF Host Routing is disabled, allowing traffic from pods to bypass the intended network policies. Per-Endpoint Routing is typically disabled by default but can be automatically enabled in certain cloud environments, including Cilium ENI on EKS, AlibabaCloud ENI, Azure IPAM, and some GKE deployments. The vulnerability is most commonly encountered in Amazon EKS with Cilium ENI mode.
Upgrade to Cilium versions 1.17.14, 1.18.8, or 1.19.2, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.cilium.io/en/stable/network/concepts/routing/#routing | [email protected] | Technical Description |
| https://docs.cilium.io/en/stable/network/kubernetes/policy/#network-policy | [email protected] | Technical Description |
| https://docs.cilium.io/en/stable/network/servicemesh/l7-traffic-management | [email protected] | Technical Description |
| https://docs.cilium.io/en/stable/operations/performance/tuning/#ebpf-host-routing | [email protected] | Technical Description |
| https://github.com/cilium/cilium/pull/44693 | [email protected] | Issue TrackingPatch |
| https://github.com/cilium/cilium/security/advisories/GHSA-hxv8-4j4r-cqgv | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cilium cilium | < 1.17.14 >= 1.18.0, < 1.18.8 >= 1.19.0, < 1.19.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |