Package
cilium-fips-1.16-operator-generic
Component
github.com/cilium/cilium
Latest update
9.2
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-49445 (GHSA-3fcv-jvfp-m4q9, critical) allows sensitive information disclosure and cluster disruption via access to the local Envoy admin socket. It is present in the Cilium 1.16 release line.
Upstream fixed this only in 1.17.14, 1.18.8, and 1.19.2 — there is no fix in the 1.16.x line. Cilium's security policy marks releases before 1.17.0 as end-of-life, and the coordinated fix shipped with no accompanying 1.16.x release; the latest 1.16.x release (1.16.19) is affected.
This package tracks the 1.16 version stream, so no in-stream update remediates it and a fix is not planned for this line. To remediate, migrate to a patched release line: 1.17.14 or later, 1.18.8 or later, or 1.19.2 or later.
References:
Status
Impact
This package is no longer supported upstream and has reached its end of life. A version upgrade is required to fix this vulnerability.
Status