CVE-2026-86831: Cross-Namespace NetworkPolicy Bypass in Amazon EKS
The Amazon EKS Network Policy Agent constructs internal pod identifiers by joining the pod name and namespace with a hyphen. Because hyphens are valid characters in both Kubernetes pod names and namespace names, an authenticated user able to create pods or namespaces in the cluster can craft two different pods in two different namespaces that end up with colliding identifiers, bypassing NetworkPolicy enforcement as a result. As a workaround ahead of patching, AWS recommends avoiding hyphens in namespace names.
Affects the Amazon VPC CNI Managed Add-on 1.14.0 through 1.22.3 and Network Policy Agent before 1.4.0; fixed in Network Policy Agent 1.4.0 and VPC CNI Managed Add-on 1.22.4.
- Amazon VPC CNI Managed Add-on 1.14.0-1.22.3
- Network Policy Agent < 1.4.0
- Network Policy Agent 1.4.0
- Amazon VPC CNI Managed Add-on 1.22.4