{"schema_version":"1.9.0","id":"CVE-2026-26963","published":"2026-02-19T23:38:36.110Z","modified":"2026-08-12T15:32:04.065253Z","aliases":["BIT-cilium-2026-26963","BIT-cilium-operator-2026-26963","BIT-hubble-relay-2026-26963","GHSA-5r23-prx4-mqg3","GO-2026-4522"],"related":["SUSE-SU-2026:0757-1","openSUSE-SU-2026:21483-1"],"summary":"Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled","details":"Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cilium/cilium","events":[{"introduced":"274205f001bb24b89d19f0fe7c3fb3aca20030c2"},{"fixed":"95896696119f33a0f5d21019182192fcdab3600f"},{"fixed":"88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885"}],"database_specific":{"cpe":"cpe:2.3:a:cilium:cilium:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.18.0"},{"fixed":"1.18.6"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.18.5","1.18.5","v1.18.4","1.18.4","v1.18.3","1.18.3","v1.18.2","1.18.2","v1.18.1","1.18.1","v1.18.0","1.18.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26963.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["13556176333476019704409188527336865777","207400423160288336577058004482172237782","287475036934113576037055184321833941265","120299526083584124651675601137997287891","334106238857523692313555793037452163910","96782046517146673854454899313175342616","157080297455277391502978688046539374818","97170476522472225462895678862371449747","36760950177920694884570442399879902864","33005109609577561227423930152760791560","218573454419051484396355006920963619233","26147997796280185288792674451601097754","294782626888401776212486181460999744778","37601426429567913880364727472966188588","112045781700694396709748631979190296986","189450623498939552499766861682296516121","42035876051696365089173174792277107266","227886270997680012871492136548711564596","317353527461955185591897307274287730806","263572736409768170563140153920941090449","323429845851650813584840989966674202398","61131354900674325898290540341539965805","106916837320220095729716536331102927242"],"threshold":0.9},"id":"CVE-2026-26963-07cc10ee","signature_type":"Line","signature_version":"v1","source":"https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885","target":{"file":"bpf/tests/tc_nodeport_l3_dev.h"}},{"deprecated":false,"digest":{"line_hashes":["97634816043596842356107074672317100869","49445410026221143781780248976814148650","169846358079537208740282300444547991807","120284695969278924601443547448543676670","136556280639408689258947997227002898604","8603968162386165218942616239681200854","50137835545936200853110328308757714214","270985023749468949531732704675123252824","324842053695157835888853293866541944141","220834697777131123974437304206722678797","123507715113930029637159260560000031712","122829936009588413057137300266454848371","6857906518848758250318922168130521094","234571022728735992207324027766122493970","71591264772387023591813830324306228434","130915357365625868643287618212363186575","21125768564000075796486998448294278519","206278814637379737884077300200248347377","337685705390888092575709022433073173818","266425283327341397914130359486421387252","45823411327317143909504033411644332639","133982870111458101042921748453688787087","339630818141674226687509738408226909699","234383958816052312044122081287005140857","78141168896021047627765671765971839827","68728976334326419329221648887375795219","63035344196629332864973045905556694896","237061928844661571610490704850745073093","111355511040087809913052593301294086396","48711593313171334151158887784997515799","91047403376392447452553074569816858249","165725330073941022858050366124516255219","197062530005985169054164394027897328019","176466863117101977723078028124833180202","120876972616321385964026195868155859636","19604129232631362180546519249449927377","159885676791808726807553306922092410589","230093557999776061153602588119789257570","332252690861376607889258176958735104873","335910078278037162509477864870763230199","86434757500686646283205758242004297330","214639813508532230860215122381713140670","114414422078400042976516718275704515651","311739935181113335387964368868305026973","260889880074080116380641490503618315351","259191428605248974053878031061112471755","236787300274276602457733744935106270970","281382573940267031580357342383830328087","316679149147302241537127823106265134598","132530779331326055675072844928464563264","207085429848066932432833113876141836589","133958169665365649923808574346408223081","35497888867353792316453486864225507740","16904358279019466596675102573919271972","134879305199303273430676465021818730573","271565950280732692448337568596454230148","134271602810779790254024470035907198597","285665613902899228693326149701367239193","234571022728735992207324027766122493970","270438424465194318000765032490094983781","238351778591885377231549249681915794674","96114979548485308278222786440166602521","337685705390888092575709022433073173818","266425283327341397914130359486421387252","45823411327317143909504033411644332639","133982870111458101042921748453688787087","339630818141674226687509738408226909699","234383958816052312044122081287005140857","68470931471795807432082085743859112662","203168793060667828698169858886704773629","21240471656448449571518865481106334678","215258157575575346921150935420249983415","73201609105278431482039985558513891060","162486429148913728637928630512781980930","91047403376392447452553074569816858249","165725330073941022858050366124516255219","197062530005985169054164394027897328019","176466863117101977723078028124833180202","120876972616321385964026195868155859636","141707410458113254034758635276231248080","135141622936065544138067006524166812930","234188080162442107395280572975393293806","89487828072528483082344895373650926786","139824963676607731135061567085677424771","256448290265329888725087725427992218083","111212619189608789825604130094279613815","212613780923537347927791665075269112919"],"threshold":0.9},"id":"CVE-2026-26963-3ec9b0cf","signature_type":"Line","signature_version":"v1","source":"https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885","target":{"file":"bpf/bpf_wireguard.c"}}],"vanir_signatures_modified":"2026-08-12T15:32:04Z"}}],"references":[{"type":"WEB","url":"https://github.com/cilium/cilium/releases/tag/v1.18.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26963.json"},{"type":"ADVISORY","url":"https://github.com/cilium/cilium/security/advisories/GHSA-5r23-prx4-mqg3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26963"},{"type":"FIX","url":"https://github.com/cilium/cilium/commit/88e28e1e62c0b1a02c3f0fc22d888ac9eefbe885"},{"type":"FIX","url":"https://github.com/cilium/cilium/pull/42892"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26963.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}