{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.17.17"
              },
              {
                "introduced": "1.18.0"
              },
              {
                "fixed": "1.18.11"
              },
              {
                "introduced": "1.19.0"
              },
              {
                "fixed": "1.19.5"
              }
            ],
            "source": [
              "CPE_RANGE",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0db95967f554c95ee21a1fb7268bb5785e563d9d"
            },
            {
              "introduced": "274205f001bb24b89d19f0fe7c3fb3aca20030c2"
            },
            {
              "fixed": "617b6b49b57901ea2671e5468b11ac7341e4beb8"
            },
            {
              "introduced": "7c6667e1e707d7f39a4af3409c2a9ebea2917d32"
            },
            {
              "fixed": "20eaccfef029cb046d70219717fb6dbbdf27a59f"
            },
            {
              "fixed": "7422068aff67ac77c7dcc57aa5b9240c91333deb"
            },
            {
              "fixed": "e0b1cef513ff910323f3743e9f3e3d86721e4857"
            },
            {
              "fixed": "f23929cff682d6ed0dc158070812cb302fc0032b"
            },
            {
              "fixed": "fd47963ea394d5e8fa4a88c40a79063430c512ca"
            }
          ],
          "repo": "https://github.com/cilium/cilium",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-w7c2-w76w-5hmj"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56742.json"
  },
  "details": "Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.",
  "id": "CVE-2026-56742",
  "modified": "2026-07-19T03:30:56.918665751Z",
  "published": "2026-07-15T19:14:07.617Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/cilium/cilium/releases/tag/v1.17.17"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cilium/cilium/releases/tag/v1.18.11"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cilium/cilium/releases/tag/v1.19.5"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56742.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/cilium/cilium/security/advisories/GHSA-w7c2-w76w-5hmj"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56742"
    },
    {
      "type": "FIX",
      "url": "https://github.com/cilium/cilium/commit/7422068aff67ac77c7dcc57aa5b9240c91333deb"
    },
    {
      "type": "FIX",
      "url": "https://github.com/cilium/cilium/commit/e0b1cef513ff910323f3743e9f3e3d86721e4857"
    },
    {
      "type": "FIX",
      "url": "https://github.com/cilium/cilium/commit/f23929cff682d6ed0dc158070812cb302fc0032b"
    },
    {
      "type": "FIX",
      "url": "https://github.com/cilium/cilium/commit/fd47963ea394d5e8fa4a88c40a79063430c512ca"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces"
}