CVE-2026-49445: Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive information or allow disruptive administrative operations, such as:
- Exposing TLS secrets
- Disrupting traffic in the cluster
- Terminating the Envoy process
This issue affects both the embedded and standalone Envoy deployment models.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49445 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →