THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fm8w-2m5w-9j7r (medium) — Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

[GHSA] GHSA-fm8w-2m5w-9j7r (medium) — Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

highgithub_advisoriesPublished 2026-09-03

GHSA-fm8w-2m5w-9j7r Severity: medium CVE: CVE-2026-56743

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

### Impact

Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under specific clu

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fm8w-2m5w-9j7r