
🚨 CRITICAL - Cilium L7 exposes world-accessible Envoy admin socket (CVE-2026-49445) When Cilium L7 functionality is enabled, the Envoy instance on cluster nodes may create a world-accessible local admin socket, exposing Envoy’s admin endpoints in both embedded and standalone Envoy deployment models. The root cause is insecure default socket permissions / improper access control on a local administrative interface. An attacker with local access on a Kubernetes node (or any workload/user able to reach the socket path) can query Envoy admin endpoints without authorization and invoke administrative operations. Impact includes exposure of sensitive data (including TLS secrets) and disruptive actions such as terminating Envoy or manipulating traffic, leading to outage and potential compromise of service confidentiality. 👉 Affected: http://github.com/cilium/cilium (Cilium with L7 enabled) < 1.19.2, < 1.18.8, < 1.17.14 | Upgrade to 1.19.2 / 1.18.8 / 1.17.14
Post summary
A critical CVE in Cilium L7 exposes world‑accessible Envoy admin sockets; the post outlines the vulnerability details and urges users to upgrade to patched versions.
