These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A medium-severity vulnerability was found in Cilium, a networking, observability, and security solution. The issue arises from incorrect handling of standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors when Cilium is configured with a custom clusterName. This results in the erroneous generation of a wildcard namespace allow rule, allowing traff [truncated]
Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. This issue has a medium CVSS score of 5.9 and is fixed in Cilium versions 1.17.17, 1.18.11, and 1.19.5. Gateway API functionality is disabled by default.
CVE-2026-49445 is a critical vulnerability in Cilium, a networking, observability, and security solution. When Cilium's L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes. This allows a local attacker to access Envoy admin endpoints, potentially exposing TLS secrets, disrupting cluster traffic, or terminating Envoy. The issue is fi [truncated]
CVE-2026-53935 is a medium-severity vulnerability in Cilium, a networking, observability, and security solution. The issue allows users with the ability to create CiliumLocalRedirectPolicies to specify arbitrary ClusterIPs, enabling traffic hijacking to Services in any namespace and bypassing namespace scoping. This affects Cilium versions prior to 1.17.16, 1.18.9, and 1.19.3. The vulnerability is fixed i [truncated]
Cilium's diagnostic utility, cilium-bugtool, inadvertently captures sensitive cryptographic material when WireGuard encryption is active. The tool is designed to collect system state for troubleshooting, but prior to the patched versions, it failed to redact WireGuard private keys from its output. Because bugtool archives are frequently shared with vendors or posted to public issue trackers, this creates [truncated]