Skip to content

fix(helm/cilium): update to v1.19.8 - #5805

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/patch-cilium
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/patch-cilium

Conversation

@tinfoild

@tinfoild tinfoild Bot commented May 18, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change OpenSSF
cilium (source) HelmChart patch 1.19.4 → 1.19.8 OpenSSF Scorecard
cilium (source) patch 1.19.2 → 1.19.8 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cilium/cilium (cilium)

v1.19.8: 1.19.8

Compare Source

Summary of Changes

Bugfixes:

  • aws/ipam: Fixed a bug where the operator would fail to allocate new IPs to nodes with prefix delegation enabled on subnets that ran out of prefixes. (Backport PR #​48604, Upstream PR #​48193, @​41ks)
  • bpf: Fix agent crash when dumping map events (Backport PR #​48379, Upstream PR #​48273, @​joestringer)
  • bpf: hostfw: tolerate unknown CT protocols and rely on policies (Backport PR #​47620, Upstream PR #​47343, @​smagnani96)
  • datapath/linux/config: fix IPV4_DIRECT_ROUTING selection on lo device (Backport PR #​48552, Upstream PR #​46861, @​fdomain)
  • Fix Hubble Relay remains running during termination (Backport PR #​48552, Upstream PR #​47942, @​xandau)
  • Fix missing config setup for 'enable-non-default-deny-policies' flag (Backport PR #​48552, Upstream PR #​48391, @​fristonio)
  • Fix nodeport egress tuple reuse for closed connections (Backport PR #​48413, Upstream PR #​48306, @​fristonio)
  • Fix restored ENI endpoints routing rule configuration when masquerading config changes (#​48422, @​fristonio)
  • fix(socketlb): only detach Cilium-owned cgroup programs (Backport PR #​48552, Upstream PR #​44066, @​puwun)
  • Fixed a bug that caused the clustermesh-apiserver etcd users managements logic to not revoke stale roles upon configuration change; users leveraging the configuration provided by the Cilium helm chart are not affected, as the target etcd role is never changed. (Backport PR #​48214, Upstream PR #​47915, @​giorio94)
  • Fixed five configuration options that were accepted but silently ignored: vtep-sync-interval, enable-xt-socket-fallback, eni-delete-on-termination with a custom CNI configuration, the enableIdentityMark Helm value outside CNI chaining mode, and lb-retry-backoff-max. (Backport PR #​48433, Upstream PR #​47635, @​aanm)
  • hubble: fix four config knobs that never reach their sink (Backport PR #​48433, Upstream PR #​47637, @​aanm)
  • operator: Emit startup logs in the configured log format (Backport PR #​48018, Upstream PR #​47890, @​HadrienPatte)
  • standalone-dns-proxy: return an error when no endpoint is found (Backport PR #​48018, Upstream PR #​47791, @​vipul-21)
  • Strengthen the validation when ingesting service backends from Cluster Mesh to prevent issues in case of specially crafted values (Backport PR #​48413, Upstream PR #​48015, @​giorio94)

CI Changes:

Misc Changes:

Other Changes:

Docker Manifests
cilium

quay.io/cilium/cilium:v1.19.8@​sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf

clustermesh-apiserver

quay.io/cilium/clustermesh-apiserver:v1.19.8@​sha256:9c44205b9e6eafed719803682669f63e0a68c549025344c0af520a94b2f3e4bc

docker-plugin

quay.io/cilium/docker-plugin:v1.19.8@​sha256:e876814edd154a8f4a2a8a8ac47a10614f7bb9a717d8cee9df352d060242e3a4

hubble-relay

quay.io/cilium/hubble-relay:v1.19.8@​sha256:f78768be216b5c00137c7d4da440724d0b49986805d361e7458cc8fe9ff976ff

operator-alibabacloud

quay.io/cilium/operator-alibabacloud:v1.19.8@​sha256:cb4a8685fc74fef8f3e97c3370faf338ba1a8b29a7d5cdc718f3926ae0093b99

operator-aws

quay.io/cilium/operator-aws:v1.19.8@​sha256:de1cfe6e9962664e69e021f1cc07ea3b4f973d4ce341d7aebabf97616dd27982

operator-azure

quay.io/cilium/operator-azure:v1.19.8@​sha256:b67fcc053fe8caa5ae5f12158c8dc568b3d16201cdea17bb78f3b61b7c1f02d7

operator-generic

quay.io/cilium/operator-generic:v1.19.8@​sha256:786ec9bb1a9344435e3e3f994bc4ed3a4a85afa6a314e98681af241f8be79833

operator

quay.io/cilium/operator:v1.19.8@​sha256:618fe8acacaa682509b19670b1228fd8184c2c4c1478e23d505ba6502e8bcf3a

v1.19.7: 1.19.7

Compare Source

Summary of Changes

Bugfixes:

  • envoy: restore http-idle-timeout as the route idle timeout source (Backport PR #​47688, Upstream PR #​47583, @​aanm)
  • Fix a BPF verifier reject on pre-v5.12 kernels, when IPv6 is enabled. (Backport PR #​47723, Upstream PR #​47765, @​julianwiedmann)
  • Fix a spurious "unable to find ifindex for interface MAC" agent warning on EKS ENI IPAM by waiting for the ENI netlink interface before configuring ingress routes and rules. (Backport PR #​47545, Upstream PR #​47295, @​aanm)
  • Fix abnormal ip allocation caused by hostnetwork pod (Backport PR #​47688, Upstream PR #​47552, @​haozhangami)
  • Fix BPF LB map key collision where HostPort/NodePort expansion could overwrite a LoadBalancer frontend when the node IP matches the LoadBalancer external IP (e.g. k3s/RKE2 L2 ServiceLB). Also fix a ~30-minute NodePort outage that occurred after deleting a LoadBalancer whose external IP was a node address with a port in the NodePort range. (Backport PR #​47414, Upstream PR #​45314, @​syedazeez337)
  • Fix bug causing Cilium to intercept traffic towards LoadBalancer VIPs when KPR is disabled, when the traffic should be delegated to kube-proxy. (Backport PR #​47414, Upstream PR #​47204, @​ajmmm)
  • Fix redirection of egressing traffic that falls in scope of a CiliumEgressGatewayPolicy, when the initial interface is a L3 interface. (Backport PR #​47757, Upstream PR #​45703, @​julianwiedmann)
  • Fix: Cilium Ingress now automatically reallocates ports and retries when cilium-envoy fails to bind due to port conflicts (Backport PR #​47410, Upstream PR #​42859, @​inerplat)
  • Fixes an issue where invalid regex on an HTTPRoute or GRPCRoute matcher is accepted but causes Envoy to NACK (Backport PR #​47468, Upstream PR #​47005, @​0xch4z)
  • fqdn/service: prune SDP identity->IP mapping on delete using newID (Backport PR #​47545, Upstream PR #​47100, @​vipul-21)
  • gateway-api: GAMMA Routes are now filtered correctly before being passed to model ingestion. (Backport PR #​47468, Upstream PR #​45294, @​youngnick)
  • ipcache: fix CIDR reference counter to use canonical prefixes (Backport PR #​47886, Upstream PR #​47208, @​iwanhae)
  • lbipam: prevent reassigning Service LoadBalancer IPs on operator restart when the existing IP belongs to a compatible sharing key group. (Backport PR #​46559, Upstream PR #​46262, @​ieth0)
  • Resolve a endpoint manager crash for restored endpoints with verbose policy logging enabled. (Backport PR #​47886, Upstream PR #​47844, @​bimmlerd)
  • wireguard: Unsubscribe node handler on shutdown (Backport PR #​47804, Upstream PR #​47614, @​HadrienPatte)

CI Changes:

Misc Changes:

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 18, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 665af35
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented May 18, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-config

+++ HelmRelease: kube-system/cilium ConfigMap: kube-system/cilium-config

@@ -52,24 +52,24 @@

   policy-deny-response: none
   enable-l7-proxy: 'true'
   enable-ipv4-masquerade: 'false'
   enable-ipv4-big-tcp: 'true'
   enable-ipv6-big-tcp: 'true'
   enable-ipv6-masquerade: 'true'
-  enable-tunnel-big-tcp: 'true'
   enable-tcx: 'true'
   datapath-mode: veth
   enable-masquerade-to-route-source: 'false'
   enable-xt-socket-fallback: 'true'
   install-no-conntrack-iptables-rules: 'false'
   iptables-random-fully: 'false'
   auto-direct-node-routes: 'true'
   direct-routing-skip-unreachable: 'true'
   enable-bandwidth-manager: 'true'
   enable-bbr: 'true'
   enable-bbr-hostns-only: 'false'
+  enable-host-firewall: 'false'
   devices: br0
   kube-proxy-replacement: 'true'
   kube-proxy-replacement-healthz-bind-address: 0.0.0.0:10256
   enable-no-service-endpoints-routable: 'true'
   bpf-lb-sock: 'true'
   bpf-lb-sock-hostns-only: 'true'
@@ -188,7 +188,9 @@

   policy-default-local-cluster: 'true'
   nat-map-stats-entries: '32'
   nat-map-stats-interval: 30s
   enable-lb-ipam: 'true'
   enable-non-default-deny-policies: 'true'
   enable-source-ip-verification: 'true'
+  enable-dynamic-config: 'true'
+  enable-drift-checker: 'true'
 
--- HelmRelease: kube-system/cilium ClusterRole: kube-system/cilium

+++ HelmRelease: kube-system/cilium ClusterRole: kube-system/cilium

@@ -50,12 +50,13 @@

   - watch
   - get
 - apiGroups:
   - cilium.io
   resources:
   - ciliumloadbalancerippools
+  - ciliumbgppeeringpolicies
   - ciliumbgpnodeconfigs
   - ciliumbgpadvertisements
   - ciliumbgppeerconfigs
   - ciliumclusterwideenvoyconfigs
   - ciliumclusterwidenetworkpolicies
   - ciliumegressgatewaypolicies
--- HelmRelease: kube-system/cilium ClusterRole: kube-system/cilium-operator

+++ HelmRelease: kube-system/cilium ClusterRole: kube-system/cilium-operator

@@ -185,12 +185,13 @@

   - ciliumgatewayclassconfigs.cilium.io
 - apiGroups:
   - cilium.io
   resources:
   - ciliumloadbalancerippools
   - ciliumpodippools
+  - ciliumbgppeeringpolicies
   - ciliumbgpclusterconfigs
   - ciliumbgpnodeconfigoverrides
   - ciliumbgppeerconfigs
   verbs:
   - get
   - list
--- HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium

+++ HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium

@@ -16,13 +16,13 @@

     rollingUpdate:
       maxUnavailable: 2
     type: RollingUpdate
   template:
     metadata:
       annotations:
-        cilium.io/cilium-configmap-checksum: d0bad4c00e267751c7ddc7b781018a786e4b0c16b180f87c1b249c9ead6c4ec4
+        cilium.io/cilium-configmap-checksum: 274f73ca301c246de40d242dcaa756e9837ecbedc89c3388bb36838180c0c163
         kubectl.kubernetes.io/default-container: cilium-agent
       labels:
         k8s-app: cilium
         app.kubernetes.io/name: cilium-agent
         app.kubernetes.io/part-of: cilium
     spec:
@@ -30,13 +30,13 @@

         appArmorProfile:
           type: Unconfined
         seccompProfile:
           type: Unconfined
       containers:
       - name: cilium-agent
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         command:
         - cilium-agent
         args:
         - --config-dir=/tmp/cilium/config-map
         startupProbe:
@@ -212,13 +212,13 @@

           mountPath: /tmp
         - name: hubble-flowlog-config
           mountPath: /flowlog-config
           readOnly: true
       initContainers:
       - name: config
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         command:
         - cilium-dbg
         - build-config
         - --k8s-api-server-urls=https://1:6443 https://2:6443 https://3:6443
         env:
@@ -240,19 +240,19 @@

           capabilities:
             add:
             - NET_ADMIN
             drop:
             - ALL
       - name: apply-sysctl-overwrites
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         env:
         - name: BIN_PATH
           value: /opt/cni/bin
         command:
-        - sh
+        - bash
         - -ec
         - |
           cp /usr/bin/cilium-sysctlfix /hostbin/cilium-sysctlfix;
           nsenter --mount=/hostproc/1/ns/mnt "/cilium-sysctlfix";
           rm /hostbin/cilium-sysctlfix
         volumeMounts:
@@ -270,13 +270,13 @@

             - SYS_ADMIN
             - SYS_CHROOT
             - SYS_PTRACE
             drop:
             - ALL
       - name: mount-bpf-fs
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         args:
         - mount | grep "/sys/fs/bpf type bpf" || mount -t bpf bpf /sys/fs/bpf
         command:
         - /bin/bash
         - -c
@@ -286,13 +286,13 @@

           privileged: true
         volumeMounts:
         - name: bpf-maps
           mountPath: /sys/fs/bpf
           mountPropagation: Bidirectional
       - name: clean-cilium-state
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         command:
         - /init-container.sh
         env:
         - name: CILIUM_ALL_STATE
           valueFrom:
@@ -330,13 +330,13 @@

         - name: cilium-cgroup
           mountPath: /sys/fs/cgroup
           mountPropagation: HostToContainer
         - name: cilium-run
           mountPath: /var/run/cilium
       - name: install-cni-binaries
-        image: quay.io/cilium/cilium:v1.19.2@sha256:7bc7e0be845cae0a70241e622cd03c3b169001c9383dd84329c59ca86a8b1341
+        image: quay.io/cilium/cilium:v1.19.8@sha256:e9f7ee1f2f3a41e44339612e3b6b88170bdde7679c9c9461f287bb27702a8ecf
         imagePullPolicy: IfNotPresent
         command:
         - /install-plugin.sh
         resources:
           limits:
             cpu: 1
--- HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium-envoy

+++ HelmRelease: kube-system/cilium DaemonSet: kube-system/cilium-envoy

@@ -28,13 +28,13 @@

     spec:
       securityContext:
         appArmorProfile:
           type: Unconfined
       containers:
       - name: cilium-envoy
-        image: quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be@sha256:60031f39669542b21aedf05a3317d14e8d3ea48255790af039b315a1c9637361
+        image: quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82@sha256:af7382699576b9e65e9184efa52eeca0b58aea70ad6e511bf260c91d9f740463
         imagePullPolicy: IfNotPresent
         command:
         - /usr/bin/cilium-envoy-starter
         args:
         - --
         - -c /var/run/cilium/envoy/bootstrap-config.json
--- HelmRelease: kube-system/cilium Deployment: kube-system/cilium-operator

+++ HelmRelease: kube-system/cilium Deployment: kube-system/cilium-operator

@@ -20,25 +20,25 @@

       maxSurge: 25%
       maxUnavailable: 50%
     type: RollingUpdate
   template:
     metadata:
       annotations:
-        cilium.io/cilium-configmap-checksum: d0bad4c00e267751c7ddc7b781018a786e4b0c16b180f87c1b249c9ead6c4ec4
+        cilium.io/cilium-configmap-checksum: 274f73ca301c246de40d242dcaa756e9837ecbedc89c3388bb36838180c0c163
       labels:
         io.cilium/app: operator
         name: cilium-operator
         app.kubernetes.io/part-of: cilium
         app.kubernetes.io/name: cilium-operator
     spec:
       securityContext:
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cilium-operator
-        image: quay.io/cilium/operator-generic:v1.19.2@sha256:e363f4f634c2a66a36e01618734ea17e7b541b949b9a5632f9c180ab16de23f0
+        image: quay.io/cilium/operator-generic:v1.19.8@sha256:786ec9bb1a9344435e3e3f994bc4ed3a4a85afa6a314e98681af241f8be79833
         imagePullPolicy: IfNotPresent
         command:
         - cilium-operator-generic
         args:
         - --config-dir=/tmp/cilium/config-map
         - --debug=
--- HelmRelease: kube-system/cilium Deployment: kube-system/hubble-relay

+++ HelmRelease: kube-system/cilium Deployment: kube-system/hubble-relay

@@ -39,13 +39,13 @@

             - ALL
           runAsGroup: 65532
           runAsNonRoot: true
           runAsUser: 65532
           seccompProfile:
             type: RuntimeDefault
-        image: quay.io/cilium/hubble-relay:v1.19.2@sha256:9987c73bad48c987fd065185535fd15a6717cbe8a8caf7fc7ef0413532cf490e
+        image: quay.io/cilium/hubble-relay:v1.19.8@sha256:f78768be216b5c00137c7d4da440724d0b49986805d361e7458cc8fe9ff976ff
         imagePullPolicy: IfNotPresent
         command:
         - hubble-relay
         args:
         - serve
         ports:
--- HelmRelease: kube-system/cilium Deployment: kube-system/hubble-ui

+++ HelmRelease: kube-system/cilium Deployment: kube-system/hubble-ui

@@ -32,13 +32,13 @@

         runAsUser: 1001
       priorityClassName: null
       serviceAccountName: hubble-ui
       automountServiceAccountToken: true
       containers:
       - name: frontend
-        image: quay.io/cilium/hubble-ui:v0.13.3@sha256:661d5de7050182d495c6497ff0b007a7a1e379648e60830dd68c4d78ae21761d
+        image: quay.io/cilium/hubble-ui:v0.13.6@sha256:049a80a03585c043d0c3121bdc518c72b0fd42bae07e4bcce0fdb8f1e88041d0
         imagePullPolicy: IfNotPresent
         ports:
         - name: http
           containerPort: 8081
         livenessProbe:
           httpGet:
@@ -55,13 +55,13 @@

         - name: tmp-dir
           mountPath: /tmp
         terminationMessagePolicy: FallbackToLogsOnError
         securityContext:
           allowPrivilegeEscalation: false
       - name: backend
-        image: quay.io/cilium/hubble-ui-backend:v0.13.3@sha256:db1454e45dc39ca41fbf7cad31eec95d99e5b9949c39daaad0fa81ef29d56953
+        image: quay.io/cilium/hubble-ui-backend:v0.13.6@sha256:83b3fc763f3d49948c306bf49b08277383e195904b9ca5c0c0022b2112628787
         imagePullPolicy: IfNotPresent
         env:
         - name: EVENTS_SERVER_PORT
           value: '8090'
         - name: FLOWS_API_ADDR
           value: hubble-relay:80
--- HelmRelease: kube-system/cilium Job: kube-system/hubble-generate-certs-a1cef3bd19

+++ HelmRelease: kube-system/cilium Job: kube-system/hubble-generate-certs-a1cef3bd19

@@ -1,66 +0,0 @@

----
-apiVersion: batch/v1
-kind: Job
-metadata:
-  name: hubble-generate-certs-a1cef3bd19
-  namespace: kube-system
-  labels:
-    k8s-app: hubble-generate-certs
-    app.kubernetes.io/name: hubble-generate-certs
-    app.kubernetes.io/part-of: cilium
-spec:
-  template:
-    metadata:
-      labels:
-        k8s-app: hubble-generate-certs
-    spec:
-      securityContext:
-        seccompProfile:
-          type: RuntimeDefault
-      containers:
-      - name: certgen
-        image: quay.io/cilium/certgen:v0.4.1@sha256:f0c656830e856d26b24b0e144df1f8b327d3b46748d76a630514111fc365b697
-        imagePullPolicy: IfNotPresent
-        securityContext:
-          capabilities:
-            drop:
-            - ALL
-          allowPrivilegeEscalation: false
-        command:
-        - /usr/bin/cilium-certgen
-        args:
-        - --ca-generate=true
-        - --ca-reuse-secret
-        - --ca-secret-namespace=kube-system
-        - --ca-secret-name=cilium-ca
-        - --ca-common-name=Cilium CA
-        env:
-        - name: CILIUM_CERTGEN_CONFIG
-          value: |
-            certs:
-            - name: hubble-server-certs
-              namespace: kube-system
-              commonName: "*.biohazard.hubble-grpc.cilium.io"
-              hosts:
-              - "*.biohazard.hubble-grpc.cilium.io"
-              usage:
-              - signing
-              - key encipherment
-              - server auth
-              - client auth
-              validity: 8760h
-            - name: hubble-relay-client-certs
-              namespace: kube-system
-              commonName: "*.hubble-relay.cilium.io"
-              hosts:
-              - "*.hubble-relay.cilium.io"
-              usage:
-              - signing
-              - key encipherment
-              - client auth
-              validity: 8760h
-      hostNetwork: false
-      serviceAccountName: hubble-generate-certs
-      automountServiceAccountToken: true
-      restartPolicy: OnFailure
-
--- HelmRelease: kube-system/cilium CronJob: kube-system/hubble-generate-certs

+++ HelmRelease: kube-system/cilium CronJob: kube-system/hubble-generate-certs

@@ -22,13 +22,13 @@

         spec:
           securityContext:
             seccompProfile:
               type: RuntimeDefault
           containers:
           - name: certgen
-            image: quay.io/cilium/certgen:v0.4.1@sha256:f0c656830e856d26b24b0e144df1f8b327d3b46748d76a630514111fc365b697
+            image: quay.io/cilium/certgen:v0.4.11@sha256:14d29a176fc96d15b154559ce1a5baf01367c10baabfa7bb8028b72f087a56f0
             imagePullPolicy: IfNotPresent
             securityContext:
               capabilities:
                 drop:
                 - ALL
               allowPrivilegeEscalation: false
--- HelmRelease: kube-system/cilium Job: kube-system/hubble-generate-certs-15bc043cd5

+++ HelmRelease: kube-system/cilium Job: kube-system/hubble-generate-certs-15bc043cd5

@@ -0,0 +1,66 @@

+---
+apiVersion: batch/v1
+kind: Job
+metadata:
+  name: hubble-generate-certs-15bc043cd5
+  namespace: kube-system
+  labels:
+    k8s-app: hubble-generate-certs
+    app.kubernetes.io/name: hubble-generate-certs
+    app.kubernetes.io/part-of: cilium
+spec:
+  template:
+    metadata:
+      labels:
+        k8s-app: hubble-generate-certs
+    spec:
+      securityContext:
+        seccompProfile:
+          type: RuntimeDefault
+      containers:
+      - name: certgen
+        image: quay.io/cilium/certgen:v0.4.11@sha256:14d29a176fc96d15b154559ce1a5baf01367c10baabfa7bb8028b72f087a56f0
+        imagePullPolicy: IfNotPresent
+        securityContext:
+          capabilities:
+            drop:
+            - ALL
+          allowPrivilegeEscalation: false
+        command:
+        - /usr/bin/cilium-certgen
+        args:
+        - --ca-generate=true
+        - --ca-reuse-secret
+        - --ca-secret-namespace=kube-system
+        - --ca-secret-name=cilium-ca
+        - --ca-common-name=Cilium CA
+        env:
+        - name: CILIUM_CERTGEN_CONFIG
+          value: |
+            certs:
+            - name: hubble-server-certs
+              namespace: kube-system
+              commonName: "*.biohazard.hubble-grpc.cilium.io"
+              hosts:
+              - "*.biohazard.hubble-grpc.cilium.io"
+              usage:
+              - signing
+              - key encipherment
+              - server auth
+              - client auth
+              validity: 8760h
+            - name: hubble-relay-client-certs
+              namespace: kube-system
+              commonName: "*.hubble-relay.cilium.io"
+              hosts:
+              - "*.hubble-relay.cilium.io"
+              usage:
+              - signing
+              - key encipherment
+              - client auth
+              validity: 8760h
+      hostNetwork: false
+      serviceAccountName: hubble-generate-certs
+      automountServiceAccountToken: true
+      restartPolicy: OnFailure
+

@tinfoild tinfoild Bot changed the title fix(helm/cilium): update 1.19.2 ➼ 1.19.4 fix(helm/group/cilium): update cilium 1.19.2 ➼ 1.19.4 Jun 2, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from 57f6a89 to d419766 Compare June 8, 2026 20:58
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from d419766 to 54bb7c4 Compare June 16, 2026 12:40
@tinfoild tinfoild Bot changed the title fix(helm/group/cilium): update cilium 1.19.2 ➼ 1.19.4 fix(helm/group/cilium): update cilium to v1.19.5 Jun 16, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from 54bb7c4 to 76393cc Compare June 19, 2026 12:30
@tinfoild tinfoild Bot changed the title fix(helm/group/cilium): update cilium to v1.19.5 fix(helm/group/cilium): update cilium (patch) Jun 19, 2026
@tinfoild tinfoild Bot changed the title fix(helm/group/cilium): update cilium (patch) fix(helm/cilium): update to v1.19.5 Jun 23, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from 76393cc to 9128756 Compare July 16, 2026 16:33
@tinfoild tinfoild Bot changed the title fix(helm/cilium): update to v1.19.5 fix(helm/cilium): update to v1.19.6 Jul 16, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from 9128756 to ef9313f Compare July 20, 2026 10:09
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 08:01 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5805 — fix(helm/cilium): update to v1.19.6
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 4


Severity Summary

Severity Count
CRITICAL 0
HIGH 2
MEDIUM / MODERATE 2
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 4

Results

Package: cilium

  • Ecosystem: HelmChart (Go)
  • Old version: 1.19.2 / 1.19.4 — VULNERABLE (4 CVEs total; 2 affect both, 2 affect 1.19.2 only)
  • New version: 1.19.6 — CLEAN

Vulnerabilities fixed by this update

  1. CVE-2026-56742 / GHSA-w7c2-w76w-5hmj — Severity: HIGH (CVSS 8.9)

    • Description: Namespaced HTTPRoutes can mirror traffic to any Service across namespaces, bypassing ReferenceGrant authorization.
    • Affected versions: < 1.19.5
    • Fixed in: 1.19.5
    • Sources: NVD, OSV.dev
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-56742
    • Status: ✅ Fixed in newer versions
  2. CVE-2026-41520 / GHSA-gj49-89wh-h4gj — Severity: HIGH (CVSS 7.9)

    • Description: Cilium-bugtool debug archive may contain sensitive data when WireGuard encryption is enabled.
    • Affected versions: < 1.19.3
    • Fixed in: 1.19.3
    • Sources: GHSA, OSV.dev
    • Evidence: GHSA-gj49-89wh-h4gj
    • Status: ✅ Fixed in newer versions (affects 1.19.2 only, not 1.19.4)
  3. CVE-2026-56743 / GHSA-fm8w-2m5w-9j7r — Severity: MEDIUM (CVSS 5.4)

    • Description: NetworkPolicy ipBlock rules with a custom clusterName may generate a wildcard namespace allow rule.
    • Affected versions: 1.19.0 — 1.19.4
    • Fixed in: 1.19.5
    • Sources: NVD, OSV.dev
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-56743
    • Status: ✅ Fixed in newer versions
  4. CVE-2026-53935 / GHSA-q6h5-q3q6-f87x — Severity: MEDIUM (CVSS 6.9)

    • Description: CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking.
    • Affected versions: 1.19.0 — < 1.19.4
    • Fixed in: 1.19.4
    • Sources: GHSA, OSV.dev
    • Evidence: GHSA-q6h5-q3q6-f87x
    • Status: ✅ Fixed in newer versions (affects 1.19.2 only, not 1.19.4)

Vulnerabilities in version 1.19.6

No known vulnerabilities found.

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2022-29178 HIGH Fixed in v1.11.5; both versions (1.19.x) are much later
CVE-2022-29179 HIGH Fixed in v1.11.5; not applicable
CVE-2023-27593 MEDIUM Fixed in v1.13.1; not applicable
CVE-2023-27594 MEDIUM Fixed in v1.13.1; not applicable
CVE-2023-27595 MEDIUM Fixed in v1.13.1; affects only v1.13.0
+50 more — All patched in versions ≤ 1.14.x — not applicable to 1.19.x

Changelog Security Highlights (1.19.2/1.19.4 → 1.19.6)

  • v1.19.5 — Fixes CVE-2026-56742 (HTTPRoute cross-namespace traffic mirror, HIGH 8.9) and CVE-2026-56743 (NetworkPolicy ipBlock bypass, MEDIUM 5.4)
  • v1.19.6 — Bugfix backports and stability improvements, no additional security patches

Recommendations

  • MERGE PRIORITY: HIGH — The old versions (1.19.2 and 1.19.4) have 2 HIGH-severity and 2 MEDIUM-severity vulnerabilities that are all remediated in 1.19.6. No new vulnerabilities introduced by the update.
  • Merge this PR promptly to remediate the exposed vulnerabilities in the running Cilium clusters.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from ef9313f to 01453d8 Compare August 24, 2026 01:14
@tinfoild tinfoild Bot changed the title fix(helm/cilium): update to v1.19.6 fix(helm/cilium): update to v1.19.7 Aug 24, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/patch-cilium branch from 01453d8 to 665af35 Compare September 16, 2026 01:08
@tinfoild tinfoild Bot changed the title fix(helm/cilium): update to v1.19.7 fix(helm/cilium): update to v1.19.8 Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant