go package report

Is cilium:cilium safe?

1 known vulnerability, worst severity MODERATE.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      medium

      severity out of 10

      epss
      0.00%
      low

      chance of exploitation in 30 days, 18th percentile of all CVEs

      xyz score
      0.0
      low

      CyberXYZ composite out of 10

      fig. 01 — CVE-2026-56742, the advisory selected below

      // 1 advisories

      CVE-2026-56742

      MODERATE
      // impact

      In Cilium clusters using Gateway API, users with permissions to create or update namespaced HTTPRoutes can mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism.

      Gateway API functionality is disabled by default.

      // patches

      This issue affects:

      • Cilium v1.19 from v1.19.0 to v1.19.4 inclusive
      • Cilium v1.18 from v1.18.0 to v1.18.10 inclusive
      • All versions of Cilium before v1.17.17

      This issue is patched in:

      • Cilium v1.19.5
      • Cilium v1.18.11
      • Cilium v1.17.17
      // workarounds

      There is no workaround to this issue. Users of this feature who are unable to upgrade can mitigate the risk by ensuring that RBAC permissions to create HTTPRoute objects are only granted to cluster admins.

      // acknowledgements

      The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @galanko for reporting the issue and @mhofstetter for their work on triaging and remediating this issue.

      // for more information

      If you have any questions or comments about this advisory, please reach out on Slack.

      If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [security@cilium.io](mailto:security@cilium.io). This is a private mailing list for the Cilium security team, and your report will be treated as top priority.

      // cvss v3.1 vector

      CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

      Attack vector
      Adjacent
      Attack complexity
      Low
      Privileges required
      High
      User interaction
      None
      Scope
      Changed
      Confidentiality
      Low
      Integrity
      Low
      Availability
      Low

      Checked 2026-09-25 at 16:49 UTC. The most recent advisory here was published 2026-07-15. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.
      Is cilium:cilium safe? go package security report | CyberXYZ