Incorrect Authorization Affecting github.com/cilium/cilium/bpf package, versions <1.17.14>=1.18.0-pre.0 <1.18.8>=1.19.0-pre.0 <1.19.2


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMCILIUMCILIUMBPF-15845081
  • published30 Mar 2026
  • disclosed26 Mar 2026
  • creditsudeephb, Champ-Goblem

Introduced: 26 Mar 2026

CVE-2026-33726  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/cilium/cilium/bpf to version 1.17.14, 1.18.8, 1.19.2 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization through the cil_to_container and bpf_lxc local-backend packet path in the datapath components. An attacker can bypass ingress network policies and reach a local backend pod by sending traffic through an L7 load balancer when per-endpoint routing is enabled, and BPF host routing is disabled.

Notes

  • The bypass affects traffic from pods to L7 Services (Envoy/GAMMA) when the selected backend is local to the same node.
  • The issue is most relevant in deployments where per-endpoint routes are enabled automatically, such as Cilium ENI on EKS and other cloud-IPAM-based setups.
  • Without the fix, packets handled on the backend pod ingress path could return CTX_ACT_OK before ingress policy enforcement, skipping the expected policy check.

CVSS Base Scores

version 4.0
version 3.1