### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
Update github.com/cilium/cilium to 1.19.4; github.com/cilium/cilium to 1.18.10; github.com/cilium/cilium to 1.17.16 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation affects github.com/cilium/cilium (go), github.com/cilium/cilium (go), github.com/cilium/cilium (go). Severity is medium. ### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/cilium/ciliumgo | >=1.19.0,<1.19.4 | 1.19.4 |
| github.com/cilium/ciliumgo | >=1.18.2,<1.18.10 | 1.18.10 |
| github.com/cilium/ciliumgo | <1.17.16 | 1.17.16 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate github.com/cilium/cilium to 1.19.4; github.com/cilium/cilium to 1.18.10; github.com/cilium/cilium to 1.17.16 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation affects github.com/cilium/cilium (go), github.com/cilium/cilium (go), github.com/cilium/cilium (go). Severity is medium. ### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher. In addition, deleting such a policy can corrupt Cilium's internal service state, causing service translation to stop working entirely for the affected Service. ### Patches This issue affects: - Cilium v1.19.0 to v1.19.3 inclusive (fixed in PR #45584) - Cilium v1.18.2 to v1.18.9 inclusive (fixed in PR #45585) - All versions of Cilium prior to v1.17.16 (fixed in PR #45412) This issue has been patched in: - Cilium v1.19.4 - Cilium v1.18.10 - Cilium v1.17.16 ### Workarounds There is no workaround to this issue. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ysksuzuki for investigating and fixing the issue. ### For more information If there are any questions or comments about this advisory, please reach out on [Slack](https://docs.cilium.io/en/latest/community/community/). To report potential vulnerabilities affecting Cilium, it strongly is encouraged to report them through the security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and reports will be treated as a top priority.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/cilium/ciliumgo | >=1.19.0,<1.19.4 | 1.19.4 |
| github.com/cilium/ciliumgo | >=1.18.2,<1.18.10 | 1.18.10 |
| github.com/cilium/ciliumgo | <1.17.16 | 1.17.16 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard