cbcvebase.
CVE-2025-64715
published 2025-11-29

CVE-2025-64715: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys…

PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.9th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toCIDRset section of the derived policy is not generated, which means outbound traffic may be permitted to more destinations than originally intended. This issue has been patched in versions 1.16.17, 1.17.10, and 1.18.4. There are no workarounds for this issue.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciliumcilium< 1.16.171.16.17
ciliumcilium——
ciliumcilium——
ciliumcilium>= 1.17.0 < 1.17.101.17.10
ciliumcilium>= 1.18.0 < 1.18.41.18.4
ciliumgithub.comcilium_cilium>= 1.17.0 < 1.17.101.17.10
github.comcilium_cilium>= 0 < 1.16.171.16.17
github.comcilium_cilium>= 1.17.0 < 1.17.101.17.10
github.comcilium_cilium>= 1.18.0 < 1.18.41.18.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.