Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
CVE-2026-56742
This high-severity CVE scores 8.9 under NVD CVSS v3. EPSS exploit probability: 0.2%, top 93% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.9
- EG Score
- 8.9(medium)
- EG Risk
- 40(Track)EG Risk 40/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity89% × 45%Exploitation0% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 7%
- KEV
- Not listed
Published
July 15, 2026
Last Modified
July 17, 2026
Advisory Details (8)
Auto-updated Jul 15, 2026Namespaced HTTPRoutes can redirect traffic to other namespaces · Advisory · cilium/cilium · GitHub
https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj1.19.5
Patch available: cilium/cilium v1.19.5
https://github.com/cilium/cilium/releases/tag/v1.19.51.18.11
Patch available: cilium/cilium v1.18.11
https://github.com/cilium/cilium/releases/tag/v1.18.111.17.17
Patch available: cilium/cilium v1.17.17
https://github.com/cilium/cilium/releases/tag/v1.17.17commit fd47963ea394 (cilium/cilium)
Fix landed in cilium/cilium commit fd47963ea394 — awaiting tagged release
https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512cacommit f23929cff682 (cilium/cilium)
Fix landed in cilium/cilium commit f23929cff682 — awaiting tagged release
https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032bcommit e0b1cef513ff (cilium/cilium)
Fix landed in cilium/cilium commit e0b1cef513ff — awaiting tagged release
https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857commit 7422068aff67 (cilium/cilium)
Fix landed in cilium/cilium commit 7422068aff67 — awaiting tagged release
https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333debWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 12× in last 7d / 35× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-03 10:36 UTCEPSS rescore
- 2026-08-02 03:35 UTCEG score recompute
- 2026-08-02 02:27 UTCEPSS rescore
- 2026-08-01 14:27 UTCEG score recompute
- 2026-08-01 04:16 UTCEPSS rescore
- 2026-07-30 23:02 UTCEG score recompute
- 2026-07-30 16:28 UTCEPSS rescore
- 2026-07-30 09:53 UTCEG score recompute
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-28 17:33 UTCEG score recompute
- 2026-07-28 15:37 UTCEPSS rescore
- 2026-07-27 15:17 UTCEG score recompute
- 2026-07-27 14:14 UTCEPSS rescore
- 2026-07-27 00:40 UTCEG score recompute
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-26 11:31 UTCEG score recompute
- 2026-07-25 14:18 UTCEPSS rescore
- 2026-07-25 14:18 UTCEPSS rescore
- 2026-07-24 14:18 UTCEPSS rescore
- 2026-07-23 14:18 UTCEPSS rescore
- 2026-07-23 03:20 UTCEG score recompute
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
Show 10 moreShow fewer
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:37 UTCEG score recompute▲ 3.00
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-17 18:00 UTCNVD updateCVSS v3 → 8.9 · severity → HIGH
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-15 19:45 UTCEG score recompute
- 2026-07-15 19:44 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-862
- CVE-2013-3960EG 9.9CRITICAL
- CVE-2015-10143EG 9.8CRITICAL
- CVE-2016-11036EG 9.8CRITICAL
- CVE-2018-11541EG 9.8CRITICAL
- CVE-2011-4183NVD 6.5EG 9.8CRITICAL
- CVE-2018-10251EG 9.8EPSS p91CRITICAL
- CVE-2018-1217EG 9.8EPSS p99CRITICAL
- CVE-2018-0015EG 9.8CRITICAL
- CVE-2017-12582EG 9.8CRITICAL
- CVE-2017-1000056EG 9.8CRITICAL
Frequently asked(5)
What is CVE-2026-56742?
When was CVE-2026-56742 disclosed?
Is CVE-2026-56742 actively exploited?
What is the CVSS score of CVE-2026-56742?
How do I remediate CVE-2026-56742?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-56742
Is Your Infrastructure Affected by CVE-2026-56742?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.