CVE-2025-30163
published 2025-03-24CVE-2025-30163: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will…
PriorityP420medium4.7CVSS 3.1
AVAACLPRNUINSCCLINAN
EPSS
0.21%
10.9th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. This issue affects: Cilium v1.16 between v1.16.0 and v1.16.7 inclusive and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.16.8 and v1.17.2. Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.16.0 < 1.16.8 | 1.16.8 |
| cilium | cilium | >= 1.17.0 < 1.17.2 | 1.17.2 |
| ciliumgithub.com | cilium_cilium | >= 1.17.0 < 1.17.2 | 1.17.2 |
| github.com | cilium_cilium | >= 1.16.0 < 1.16.8 | 1.16.8 |
| github.com | cilium_cilium | >= 1.17.0 < 1.17.2 | 1.17.2 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
vendor_redhat3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cilium: Node based network policies may incorrectly allow workload traffic
vendor_redhat·2025-03-24·CVSS 3.4
CVE-2025-30163 [LOW] CWE-863 cilium: Node based network policies may incorrectly allow workload traffic
cilium: Node based network policies may incorrectly allow workload traffic
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. This issue affects: Cilium v1.16 between v1.16.0 and v1.16.7 inclusive and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.16.8 and v1.17.2. Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints.
A flaw was found in Cilium package.
OSV
Cilium node based network policies may incorrectly allow workload traffic in github.com/cilium/cilium
osv·2025-03-25
CVE-2025-30163 Cilium node based network policies may incorrectly allow workload traffic in github.com/cilium/cilium
Cilium node based network policies may incorrectly allow workload traffic in github.com/cilium/cilium
Cilium node based network policies may incorrectly allow workload traffic in github.com/cilium/cilium
GHSA
Cilium node based network policies may incorrectly allow workload traffic
ghsa·2025-03-24
CVE-2025-30163 [LOW] CWE-863 Cilium node based network policies may incorrectly allow workload traffic
Cilium node based network policies may incorrectly allow workload traffic
### Impact
[Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium.
### Patches
This issue was fixed by https://github.com/cilium/cilium/pull/36657.
This issue affects:
- Cilium v1.16 between v1.16.0 and v1.16.7 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.1 inclusive
This issue is fixed in:
- Cilium v1.16.8
- Cilium v1.17.2
### Workarounds
Users can work around this issue by ensuring that the labels used in `fromNodes` and
OSV
Cilium node based network policies may incorrectly allow workload traffic
osv·2025-03-24
CVE-2025-30163 [LOW] Cilium node based network policies may incorrectly allow workload traffic
Cilium node based network policies may incorrectly allow workload traffic
### Impact
[Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium.
### Patches
This issue was fixed by https://github.com/cilium/cilium/pull/36657.
This issue affects:
- Cilium v1.16 between v1.16.0 and v1.16.7 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.1 inclusive
This issue is fixed in:
- Cilium v1.16.8
- Cilium v1.17.2
### Workarounds
Users can work around this issue by ensuring that the labels used in `fromNodes` and
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-30163 cilium: Node based network policies may incorrectly allow workload traffic
bugzilla·2025-03-24·CVSS 4.7
CVE-2025-30163 [MEDIUM] CVE-2025-30163 cilium: Node based network policies may incorrectly allow workload traffic
CVE-2025-30163 cilium: Node based network policies may incorrectly allow workload traffic
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. This issue affects: Cilium v1.16 between v1.16.0 and v1.16.7 inclusive and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.16.8 and v1.17.2. Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints.
Wiz
CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-33726 [LOW] CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33726 :
Cilium vulnerability analysis and mitigation
eni.enabled
alibabacloud.enabled
azure.enabled
gke.enabled
Source : NVD
## 4.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Cilium
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kubescape-operator
kubescape-operator-fips
Sources
Chainguard Has Fix Added at: Mar 29, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has F
Wiz
CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-26963 [LOW] CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26963 :
Cilium vulnerability analysis and mitigation
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
Source : NVD
## 5.4
Score
Published February 20, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Cilium
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
github.com/cilium/cilium
cilium-1.18
Sources
GoLang Severity MEDIUM Has Fix Added at: Feb 20,
2025-03-24
Published