CVE-2025-32793
published 2025-04-21CVE-2025-32793: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2…
PriorityP417medium4CVSS 3.1
AVNACHPRNUINSCCLINAN
EPSS
0.14%
3.7th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. This issue has been patched in versions 1.15.16, 1.16.9, and 1.17.3. There are no workarounds available for this issue.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.13.0 < 1.15.16 | 1.15.16 |
| cilium | cilium | >= 1.16.0 < 1.16.9 | 1.16.9 |
| cilium | cilium | >= 1.17.0 < 1.17.3 | 1.17.3 |
| github.com | cilium_cilium | >= 1.13.0 < 1.15.16 | 1.15.16 |
| github.com | cilium_cilium | >= 1.16.0 < 1.16.9 | 1.16.9 |
| github.com | cilium_cilium | >= 1.17.0 < 1.17.3 | 1.17.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
osv·2025-04-22
CVE-2025-32793 In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
OSV
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
osv·2025-04-21
CVE-2025-32793 [MEDIUM] In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
### Impact
When using [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg) in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium.
### Patches
This issue has been patched in https://github.com/cilium/cilium/pull/38592.
This issue affects:
- Cilium v1.15 between v1.15.0 and v1.15.15 inclusive
- Cilium v1.16 between v1.16.0 and v1.16.8 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.2 inclusive
This issue is fixed in:
- Cilium v1.15.16
- Cilium v1.16.9
- Cilium v1.17.3
### Workarounds
There is
GHSA
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
ghsa·2025-04-21
CVE-2025-32793 [MEDIUM] CWE-319 In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
### Impact
When using [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg) in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium.
### Patches
This issue has been patched in https://github.com/cilium/cilium/pull/38592.
This issue affects:
- Cilium v1.15 between v1.15.0 and v1.15.15 inclusive
- Cilium v1.16 between v1.16.0 and v1.16.8 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.2 inclusive
This issue is fixed in:
- Cilium v1.15.16
- Cilium v1.16.9
- Cilium v1.17.3
### Workarounds
There is
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-33726 [LOW] CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33726 :
Cilium vulnerability analysis and mitigation
eni.enabled
alibabacloud.enabled
azure.enabled
gke.enabled
Source : NVD
## 4.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Cilium
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kubescape-operator
kubescape-operator-fips
Sources
Chainguard Has Fix Added at: Mar 29, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has F
Wiz
CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-26963 [LOW] CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26963 :
Cilium vulnerability analysis and mitigation
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
Source : NVD
## 5.4
Score
Published February 20, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Cilium
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
github.com/cilium/cilium
cilium-1.18
Sources
GoLang Severity MEDIUM Has Fix Added at: Feb 20,
2025-04-21
Published