CVE-2025-64715
published 2025-11-29CVE-2025-64715: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys…
PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.9th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toCIDRset section of the derived policy is not generated, which means outbound traffic may be permitted to more destinations than originally intended. This issue has been patched in versions 1.16.17, 1.17.10, and 1.18.4. There are no workarounds for this issue.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | < 1.16.17 | 1.16.17 |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.17.0 < 1.17.10 | 1.17.10 |
| cilium | cilium | >= 1.18.0 < 1.18.4 | 1.18.4 |
| ciliumgithub.com | cilium_cilium | >= 1.17.0 < 1.17.10 | 1.17.10 |
| github.com | cilium_cilium | >= 0 < 1.16.17 | 1.16.17 |
| github.com | cilium_cilium | >= 1.17.0 < 1.17.10 | 1.17.10 |
| github.com | cilium_cilium | >= 1.18.0 < 1.18.4 | 1.18.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
osv·2025-12-15
CVE-2025-64715 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
GHSA
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
ghsa·2025-12-01
CVE-2025-64715 [MEDIUM] CWE-284 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
### Impact
`CiliumNetworkPolicy`s which use `egress.toGroups.aws.securityGroupsIds` to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toCIDRset section of the derived policy is not generated, which means outbound traffic may be permitted to more destinations than originally intended.
### Patches
This issue has been patched in:
* Cilium v1.18.4
* Cilium v1.17.10
* Cilium v1.16.17
### This issue affects:
- Cilium v1.18 between v1.18.0 and v1.18.3 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.9 inclusive
- Cilium v1.16.16 and below
### Workar
OSV
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
osv·2025-12-01
CVE-2025-64715 [MEDIUM] Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
### Impact
`CiliumNetworkPolicy`s which use `egress.toGroups.aws.securityGroupsIds` to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toCIDRset section of the derived policy is not generated, which means outbound traffic may be permitted to more destinations than originally intended.
### Patches
This issue has been patched in:
* Cilium v1.18.4
* Cilium v1.17.10
* Cilium v1.16.17
### This issue affects:
- Cilium v1.18 between v1.18.0 and v1.18.3 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.9 inclusive
- Cilium v1.16.16 and below
### Workar
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-33726 [LOW] CVE-2026-33726 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33726 :
Cilium vulnerability analysis and mitigation
eni.enabled
alibabacloud.enabled
azure.enabled
gke.enabled
Source : NVD
## 4.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Cilium
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kubescape-operator
kubescape-operator-fips
Sources
Chainguard Has Fix Added at: Mar 29, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 29, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Mar 29, 2026
Linux Severity MEDIUM Has F
Wiz
CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2026-26963 [LOW] CVE-2026-26963 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26963 :
Cilium vulnerability analysis and mitigation
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version 1.18.6.
Source : NVD
## 5.4
Score
Published February 20, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Cilium
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
github.com/cilium/cilium
cilium-1.18
Sources
GoLang Severity MEDIUM Has Fix Added at: Feb 20,
https://github.com/cilium/cilium/commit/a385856b59c8289cc7273fa3a3062bbf0ef96c97https://github.com/cilium/cilium/releases/tag/v1.16.17https://github.com/cilium/cilium/releases/tag/v1.17.10https://github.com/cilium/cilium/releases/tag/v1.18.4https://github.com/cilium/cilium/security/advisories/GHSA-38pp-6gcp-rqvm
2025-11-29
Published