Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-49445

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Back to all
CVE

CVE-2026-49445

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:

  • Exposing TLS secrets
  • Disrupting traffic in the cluster
  • Terminating the Envoy process  

This issue affects both the embedded and standalone Envoy deployment models.

Patches

This issue affects:

  • Cilium v1.19 between v1.19.0 and v1.19.1 inclusive
  • Cilium v1.18 between v1.18.0 and v1.18.7 inclusive
  • All versions of Cilium prior to v1.17.14

This issue has been patched in https://github.com/cilium/cilium/pull/44512, included in:

  • Cilium v1.19.2
  • Cilium v1.18.8
  • Cilium v1.17.14

Workarounds

There is no known workaround to this issue.

Acknowledgements

The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to moemen for reporting the issue and 0xch4z for their work on triaging and remediating this issue.

For more information

If there are any questions or comments about this advisory, please reach out on [Slack (https://docs.cilium.io/en/latest/community/community/).

If anyone thinks they have found a vulnerability affecting Cilium, it is strongly encouraged to report it to the security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and the report will be treated as a top priority.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
C
H
U
9.2
-
3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H

Related Resources

No items found.

References

https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9, https://github.com/cilium/cilium/pull/44512, https://github.com/cilium/cilium

Severity

9.2

CVSS Score
0
10

Basic Information

Base CVSS
9.2
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
1.19.0,v0.0.0-20240318040020-c4bd58d18c0f,v1.16.0-pre.1,v1.18.0-pre.0,v1.19.0-pre.0,v0.0.0-20230512055023-2ebc2738d932,v1.14.0-rc.0,v0.0.0-20180905034512-fc806381d415,v1.3.0-rc1
Fix Available
1.19.2,v0.0.0-20260303103717-a9f09fcb9786,v1.17.14,v1.18.8,v1.19.2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading