<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:03:28 +0000</lastBuildDate>
    <item>
      <title>BIT-cilium-2026-56743 — Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured wi…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-cilium-2026-56743</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cilium&lt;/p&gt;
&lt;p&gt;Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cilium&lt;/p&gt;
&lt;p&gt;Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-cilium-2026-56743</guid>
    </item>
    <item>
      <title>EUVD-2026-338218</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338218</link>
      <description>EUVD-2026-338218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338218</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56743</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56743</link>
      <description>&lt;p&gt;Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56743</guid>
    </item>
    <item>
      <title>GHSA-fm8w-2m5w-9j7r — Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured wi…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fm8w-2m5w-9j7r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cilium/cilium&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations.&lt;/p&gt;
&lt;p&gt;When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `&amp;#34;any&amp;#34;` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label selector to the policy&amp;#39;s allowed Layer 3 rules, which allows traffic from other workloads in the same namespace as the subject of the policy.&lt;/p&gt;
&lt;p&gt;Example policy affected by this issue:
```
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: test-server
  namespace: default
spec:
  podSelector:
    matchLabels:
      app: test-server
  policyTypes:
  - Ingress
  ingress:
  - from:
    - ipBlock:
        cidr: 192.0.2.3
```&lt;/p&gt;
&lt;p&gt;In affected versions, this policy erroneously allows the `test-server` Pod in the `default` namespace to receive any traffic from other workloads running in the `default` namespace.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been patched in:&lt;/p&gt;
&lt;p&gt;- Cilium v1.19.5&lt;/p&gt;
&lt;p&gt;Releases below v1.19.0 are not affected.&lt;/p&gt;
&lt;p&gt;### This issue affects:&lt;/p&gt;
&lt;p&gt;- Cilium v1.19 between v1.19.0 and v1.19.4 inclusive&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Developers can create the equivalent policy using CiliumNetworkPolicy [fromCIDR expressions](https://docs.cilium.io/en/stable/security/policy/layer3/#ip-cidr-based). CiliumNetwo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cilium/cilium&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific cluster configurations.&lt;/p&gt;
&lt;p&gt;When Cilium deployment is configured with a specific custom `clusterName` (rather than the default `&amp;#34;any&amp;#34;` value), the parser incorrectly instantiates a pod selector on selectorless peer definitions. This leads to Cilium appending an unintended wildcard namespace label selector to the policy&amp;#39;s allowed Layer 3 rules, which allows traffic from other workloads in the same namespace as the subject of the policy.&lt;/p&gt;
&lt;p&gt;Example policy affected by this issue:
```
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: test-server
  namespace: default
spec:
  podSelector:
    matchLabels:
      app: test-server
  policyTypes:
  - Ingress
  ingress:
  - from:
    - ipBlock:
        cidr: 192.0.2.3
```&lt;/p&gt;
&lt;p&gt;In affected versions, this policy erroneously allows the `test-server` Pod in the `default` namespace to receive any traffic from other workloads running in the `default` namespace.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been patched in:&lt;/p&gt;
&lt;p&gt;- Cilium v1.19.5&lt;/p&gt;
&lt;p&gt;Releases below v1.19.0 are not affected.&lt;/p&gt;
&lt;p&gt;### This issue affects:&lt;/p&gt;
&lt;p&gt;- Cilium v1.19 between v1.19.0 and v1.19.4 inclusive&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Developers can create the equivalent policy using CiliumNetworkPolicy [fromCIDR expressions](https://docs.cilium.io/en/stable/security/policy/layer3/#ip-cidr-based). CiliumNetwo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fm8w-2m5w-9j7r</guid>
    </item>
  </channel>
</rss>
