fix(deps): update module github.com/cilium/cilium to v1.17.14 [security] (v1.4)#4803
Open
cilium-renovate[bot] wants to merge 1 commit intov1.4from
Open
Conversation
Signed-off-by: cilium-renovate[bot] <134692979+cilium-renovate[bot]@users.noreply.github.com>
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: pkg/k8s/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.17.10→v1.17.14Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
BIT-cilium-2026-33726 / BIT-cilium-operator-2026-33726 / BIT-hubble-relay-2026-33726 / CVE-2026-33726 / GHSA-hxv8-4j4r-cqgv / GO-2026-4856
More information
Details
Impact
Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled.
Per-Endpoint Routing is disabled by default, but is automatically enabled in deployments using cloud IPAM, including Cilium ENI on EKS (
eni.enabled), AlibabaCloud ENI (alibabacloud.enabled), Azure IPAM (azure.enabled, but not AKS BYOCNI), and some GKE deployments (gke.enabled; managed offerings such as GKE Dataplane V2 may use different defaults). It is typically not enabled in tunneled deployments, and chaining deployments are not affected. In practice, Amazon EKS with Cilium ENI mode is likely the most common affected environment.Patches
This issue was fixed by #44693.
This issue affects:
This issue is fixed in:
Workarounds
Disclaimer: There is currently no officially verified or comprehensive workaround for this issue. The only option would be to disable per-endpoint routes, but this will likely cause disruptions to ongoing connections, and potential conflicts if running in cloud providers.
Acknowledgements
The Cilium community has worked together with members of the Northflank and Isovalent teams to prepare these mitigations. Cilium thanks @sudeephb and @Champ-Goblem for reporting the issue and to @smagnani96 and @julianwiedmann for helping with the resolution.
For more information
Anyone who believes a vulnerability affecting Cilium has been found is strongly encouraged to report it to the security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and any such report will be treated as top priority. Please also address any comments or questions on this advisory to the same mailing list.
Severity
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic in github.com/cilium/cilium
BIT-cilium-2026-33726 / BIT-cilium-operator-2026-33726 / BIT-hubble-relay-2026-33726 / CVE-2026-33726 / GHSA-hxv8-4j4r-cqgv / GO-2026-4856
More information
Details
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic in github.com/cilium/cilium
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Release Notes
cilium/cilium (github.com/cilium/cilium)
v1.17.14: 1.17.14Compare Source
Summary of Changes
Bugfixes:
CI Changes:
Misc Changes:
d1e2e92(v1.17) (#44481, @cilium-renovate[bot])e3f9456(v1.17) (#44798, @cilium-renovate[bot])f512d81(v1.17) (#44581, @cilium-renovate[bot])b8788ab(v1.17) (#44482, @cilium-renovate[bot])find /sys/fs/bpfin bugtool output (Backport PR #44591, Upstream PR #38980, @ti-mo)Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.17.14@​sha256:cdcfab5b4466d607f713d1ada281ee4513dd3982eb2c48ef2d0cc708cc3d1ba3clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.17.14@​sha256:6cc4e47b2a50649e739dbb61f266497e7ef53d048b60dc32ba563bd4efd7f0badocker-plugin
quay.io/cilium/docker-plugin:v1.17.14@​sha256:087072e60566cc37e21facec0e4096d49bef2e83cd340896ae477a7746819067hubble-relay
quay.io/cilium/hubble-relay:v1.17.14@​sha256:ce5b991bb011fa744c94e04fd7f1a7d3c8e3ce7d2da0652766abe6c468ead990operator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.17.14@​sha256:bdfa469e453986b995632f889cfb90bc501b80a809ff4b8be8d236eba5fcc2cboperator-aws
quay.io/cilium/operator-aws:v1.17.14@​sha256:182c13e6edda041bfc885932d5e87b1d8ac3588f6f6af309944efee46a2193b2operator-azure
quay.io/cilium/operator-azure:v1.17.14@​sha256:a462e7265ee34a667905c6144b7aa5d5ee8328ee1a4eca3f44bdc1463cc69741operator-generic
quay.io/cilium/operator-generic:v1.17.14@​sha256:773886ec9337f6628ba84e36ac7e3e554c1622024fc2a8b04a3377970aee8889operator
quay.io/cilium/operator:v1.17.14@​sha256:2113d66000847f39135722c61545ddb2c1bbd9fc4479f10dca175fc4bf9bda1bv1.17.13: 1.17.13Compare Source
Summary of Changes
Minor Changes:
CI Changes:
Misc Changes:
b3255e7(v1.17) (#44254, @cilium-renovate[bot])e226d63(v1.17) (#43985, @cilium-renovate[bot])c213114(v1.17) (#43986, @cilium-renovate[bot])cd1dba6(v1.17) (#43987, @cilium-renovate[bot])f9f84bd(v1.17) (#44255, @cilium-renovate[bot])Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.17.13@​sha256:1e3907ba8815e2e474ea8da25876911af2da0ae07c04eaa87a326ba4343aa539clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.17.13@​sha256:3aeee4e88b68934f45faf211a1e6b1b7310ac31b2dda448f5df77860c57a71fadocker-plugin
quay.io/cilium/docker-plugin:v1.17.13@​sha256:a37e314f585cb57165605c50449ed9fb4458d766689a328405644920ae6de6eehubble-relay
quay.io/cilium/hubble-relay:v1.17.13@​sha256:0c49b7363157849623099de9fc9378da7146f49e7d5f602d113223542b789aceoperator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.17.13@​sha256:a383d4c3896d150aad8e6f1d54df942e98e83033f381e5b9a7f424d1caf77471operator-aws
quay.io/cilium/operator-aws:v1.17.13@​sha256:8c6faae3a985690d35f77309a1300f4dd0e8f11544537e2589ffa3c0132d978aoperator-azure
quay.io/cilium/operator-azure:v1.17.13@​sha256:4ad4c0cc236efe751f33fb1449a056af10654bc9cb7407862d412bc065ba6185operator-generic
quay.io/cilium/operator-generic:v1.17.13@​sha256:c2582d9eaeec598de9cd8815a3ed20caade17c26858eea672cff3240b0970983operator
quay.io/cilium/operator:v1.17.13@​sha256:581d5d54e5993be947cbce34fd5cb3401d124e2859dad0c947272f911b9b0d16v1.17.12: 1.17.12Compare Source
Summary of Changes
Major Changes:
Bugfixes:
processRequestStream(Backport PR #43613, Upstream PR #43609, @mhofstetter)CI Changes:
Misc Changes:
2383baa(v1.17) (#43666, @cilium-renovate[bot])54528d1(v1.17) (#43417, @cilium-renovate[bot])a61b432(v1.17) (#43544, @cilium-renovate[bot])Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.17.12@​sha256:f525e12698149b3958024599493d9cc56fadbc46c9250cbced8016e9b9b679e5clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.17.12@​sha256:4c26ba1e62c44df28d58fc5bd8e1a87aa1d442aa081ff3e170e122f0106cd006docker-plugin
quay.io/cilium/docker-plugin:v1.17.12@​sha256:4a17b4cfa041a0206242b2ead6c83598c2aec34c4d470c614d673840427f04e0hubble-relay
quay.io/cilium/hubble-relay:v1.17.12@​sha256:ef2a294e81f91c74b729794f7098d61ee21b4c2efa11461c4e62623f5b5c240coperator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.17.12@​sha256:fda5705cb82d601172b25f098031960bf79cad86a43acc180e7176be001b263foperator-aws
quay.io/cilium/operator-aws:v1.17.12@​sha256:9b9aebf43f6ddd59a2db05a523422842d69c88662a901effabda8bca242136beoperator-azure
quay.io/cilium/operator-azure:v1.17.12@​sha256:69c9aea1b3d41017fc5f0066b818d4b8c123067f53feef4d855baad9daeb6515operator-generic
quay.io/cilium/operator-generic:v1.17.12@​sha256:0b675406b1e43b198962d4f9c3a5ba6bb68fc98836cba05b224860109112f6d9operator
quay.io/cilium/operator:v1.17.12@​sha256:42d19b80461bad1d0f4f0f08aa23ff5a5e3950ef516c1c514cb053144da336b8v1.17.11: 1.17.11Compare Source
Summary of Changes
Bugfixes:
CI Changes:
Misc Changes:
d80cd69(v1.17) (#43319, @cilium-renovate[bot])7b13449(v1.17) (#42806, @cilium-renovate[bot])e3fb71a(v1.17) (#43320, @cilium-renovate[bot])2b7c93f(v1.17) (#43185, @cilium-renovate[bot])Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.17.11@​sha256:260f7892b1e554f57618022070960bfbb78fc7a679feb934299f907e47ea8992clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.17.11@​sha256:cd298620390b388320b4e2178ab81f928160d410789eb590299e5d3877badacedocker-plugin
quay.io/cilium/docker-plugin:v1.17.11@​sha256:b8561a129770de63b776e7b7d3d02b8e5bb332507a14757284e9423f45fb1224hubble-relay
quay.io/cilium/hubble-relay:v1.17.11@​sha256:e3fd2efae4563f06a15565af6c7e5b766ebb301b372acaa68e2f9184bafc98a6operator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.17.11@​sha256:312dc6c796c809255dee302eebc613909500c5fe153df3f3b025c067f44e03bdoperator-aws
quay.io/cilium/operator-aws:v1.17.11@​sha256:363779644fc8a6d1f503140548fb3e8d0a861e27d2ee2ff4d86d75802beeea6eoperator-azure
quay.io/cilium/operator-azure:v1.17.11@​sha256:0782670b423ae84bef6728dd8626e2a6bd0512737207aa128392d70450fe5418operator-generic
quay.io/cilium/operator-generic:v1.17.11@​sha256:dbd985d5b5602a4f2ae4aafd1332829bdd7d3bf452164b7288c90e3470590422operator
quay.io/cilium/operator:v1.17.11@​sha256:5158e04f5a4e6d1a60f56e1aa5c23db685edd22d54cad23a06441187a38272a5Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Renovate Bot.