CVE-2026-26963: Cilium Wireguard Ingress Policy Bypass
Returning `CTX_ACT_OK` at the end of `handle_ipv4` or `handle_ipv6` without handling host delivery allows packets from WireGuard or similar network tunnels to bypass host ingress network policies. Ensure that host-bound packets are correctly redirected (e.g. using `ipv4_host_delivery` or `ipv6_host_delivery`) rather than being permitted by default.
greprules fetch cve-2026-26963-cilium-wireguard-ingress-policy-bypass --engine opengrepDescription
Returning `CTX_ACT_OK` at the end of `handle_ipv4` or `handle_ipv6` without handling host delivery allows packets from WireGuard or similar network tunnels to bypass host ingress network policies. Ensure that host-bound packets are correctly redirected (e.g. using `ipv4_host_delivery` or `ipv6_host_delivery`) rather than being permitted by default.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.