critical

CVE-2026-49445

Go · github.com/cilium/cilium

Summary

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Severity
critical
CVSS
9.2
EPSS
0.2% (p6)
CWE
CWE-862
Also known as
GHSA-3fcv-jvfp-m4q9
Published
2026-07-06
Updated
2026-07-06

Advisory details

Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:

This issue affects both the embedded and standalone Envoy deployment models.

Patches

This issue affects:

This issue has been patched in https://github.com/cilium/cilium/pull/44512, included in:

Workarounds

There is no known workaround to this issue.

Acknowledgements

The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to moemen for reporting the issue and 0xch4z for their work on triaging and remediating this issue.

For more information

If there are any questions or comments about this advisory, please reach out on [Slack (https://docs.cilium.io/en/latest/community/community/).

If anyone thinks they have found a vulnerability affecting Cilium, it is strongly encouraged to report it to the security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and the report will be treated as a top priority.

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.