CVE-2026-41520
published 2026-05-08CVE-2026-41520: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of…
PriorityP420medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.08%
0.1th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. This issue has been patched in versions 1.17.15, 1.18.9, and 1.19.3.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | < 1.17.15 | 1.17.15 |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.18.0 < 1.18.9 | 1.18.9 |
| cilium | cilium | >= 1.19.0 < 1.19.3 | 1.19.3 |
| github.com | cilium_cilium | >= 0 < 1.17.15 | 1.17.15 |
| github.com | cilium_cilium | >= 1.18.0 < 1.18.9 | 1.18.9 |
| github.com | cilium_cilium | >= 1.19.0 < 1.19.3 | 1.19.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cilium up to 1.17.14/1.18.8/1.19.2 information disclosure (GHSA-gj49-89wh-h4gj)
vuldb·2026-05-09·CVSS 7.9
CVE-2026-41520 [HIGH] Cilium up to 1.17.14/1.18.8/1.19.2 information disclosure (GHSA-gj49-89wh-h4gj)
A vulnerability has been found in Cilium up to 1.17.14/1.18.8/1.19.2 and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-41520. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
GHSA
Cillium exposes sensitive information included in the cilium-bugtool debug archive
ghsa·2026-04-25
CVE-2026-41520 [HIGH] CWE-200 Cillium exposes sensitive information included in the cilium-bugtool debug archive
Cillium exposes sensitive information included in the cilium-bugtool debug archive
### Impact
The output of `cilium-bugtool` can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled.
Users of [WireGuard Transparent Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/) are affected.
The sensitive data is the WireGuard private key (`cilium_wg0.key`) used for node-to-node encrypted communication
`cilium-bugtool` is a debugging tool that is typically invoked manually and does not run during the normal operation of a Cilium cluster. It is also invoked when gathering sysdumps using the Cilium CLI's `cilium sysdump` command.
### Patches
This issue affects:
- Cilium v1.19 between v1.19.0 and v1.19.2 inclusive
-
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-08
Published