Github.Com Cilium Cilium vulnerabilities
36 known vulnerabilities affecting github.com/cilium_cilium.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW4
Vulnerabilities
Page 1 of 2
CVE-2023-27595P3MEDIUM≥ 1.13.0, < 1.13.12023-03-17
CVE-2023-27595 [MEDIUM] CWE-755 Cilium eBPF filters may be temporarily removed during agent restart
Cilium eBPF filters may be temporarily removed during agent restart
### Impact
When Cilium is started, there is a short period when Cilium eBPF programs are not attached to the host. During this period, the host does not implement any of Cilium's featureset. This can cause disruption to newly established connections during this period due to the lack of Load Balancing, or can cause Network Polic
ghsaosv
CVE-2024-47825P3MEDIUM≥ 1.15.0, < 1.15.10≥ 1.14.0, < 1.14.162024-10-21
CVE-2024-47825 [MEDIUM] CWE-1038 Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
### Impact
A policy rule denying a prefix that is broader than /32 may be ignored if there is
- A policy rule referencing a more narrow prefix (`CIDRSet` or `toFQDN`) **and**
- This narrower policy rule specifies either `enableDefaultDeny: false` or `- toEntities: all`
Note that a rul
ghsaosv
CVE-2026-56742P3MEDIUM≥ 0, < 1.17.17≥ 1.19.0, < 1.19.52026-09-24
CVE-2026-56742 [MEDIUM] CWE-862 Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
### Impact
In Cilium clusters using [Gateway API](https://docs.cilium.io/en/stable/network/servicemesh/gateway-api/gateway-api/), users with permissions to create or update namespaced HTTPRoutes can mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism.
Gateway API funct
ghsa
CVE-2023-39347P3MEDIUM≥ 1.13.0, < 1.13.7≥ 1.14.0, < 1.14.2+1 more2023-09-26
CVE-2023-39347 [MEDIUM] CWE-345 Kubernetes users may update Pod labels to bypass network policy
Kubernetes users may update Pod labels to bypass network policy
### Impact
An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies.
This issue arises due to the fact that on pod update, Cilium incorrectly uses user-provided pod labels to select the policies which apply to the workload in question.
This can affect:
* Cilium network policies that use t
ghsaosv
CVE-2026-49445P3CRITICAL≥ 1.19.0, < 1.19.2≥ 1.18.0, < 1.18.8+1 more2026-07-06
CVE-2026-49445 [CRITICAL] CWE-862 Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
### Impact
When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Dependin
ghsa
CVE-2023-27594P3MEDIUM≥ 0, < 1.11.15≥ 1.12.0, < 1.12.8+1 more2023-03-17
CVE-2023-27594 [MEDIUM] CWE-285 Potential network policy bypass when routing IPv6 traffic
Potential network policy bypass when routing IPv6 traffic
## Impact
Under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from the host on which Cilium is running. As a consequence, network policies for that cluster might be bypassed, depending on the specific network policies enabled. Only IPv6 traffic is impacted by this
ghsaosv
CVE-2024-28248P3HIGH≥ 1.13.9, < 1.13.13≥ 1.14.0, < 1.14.8+1 more2024-03-18
CVE-2024-28248 [HIGH] CWE-693 Intermittent HTTP policy bypass
Intermittent HTTP policy bypass
### Impact
Cilium's [HTTP policies](https://docs.cilium.io/en/stable/security/policy/language/#http) are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped.
### Patches
This issue affects:
* Cilium v1.13 between v1.13.9 and v1.13.12 inclusive
* Cilium v1.14 between v1.14.0 and v1.14.7
ghsaosv
CVE-2024-42486P3MEDIUM≥ 1.16.0, < 1.16.1≥ 1.15.0, < 1.15.82024-08-16
CVE-2024-42486 [MEDIUM] CWE-200 Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API
Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API
### Impact
Due to ReferenceGrant changes not being immediately propagated in Cilium's GatewayAPI controller, Gateway resources are able to access secrets in other namespaces after the associated ReferenceGrant has been revoked. This can lead to Gateways continuing to establish sessions using secrets t
ghsaosv
CVE-2023-41333P3MEDIUM≥ 1.14.0, < 1.14.2≥ 1.13.0, < 1.13.7+1 more2023-09-27
CVE-2023-41333 [MEDIUM] CWE-306 Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
### Impact
An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium cluster, potentially bypassing policy enforcement in other namespaces.
By using a crafted `endpointSelector` that uses the `DoesNotExist` operator on t
ghsaosv
CVE-2022-29179P3HIGH≥ 1.11.0, < 1.11.5≥ 1.10.0, < 1.10.11+1 more2022-05-24
CVE-2022-29179 [HIGH] CWE-269 Improper Privilege Management in Cilium
Improper Privilege Management in Cilium
### Impact
If an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can leverage Cilium's Kubernetes service account to gain access to cluster privileges that are more permissive than what is minimally required to operate Cilium. In affected releases, this service account had access to modify and delete `Pod`
ghsaosv
CVE-2022-29178P3HIGH≥ 1.11.0, < 1.11.5≥ 1.10.0, < 1.10.11+1 more2022-05-24
CVE-2022-29178 [HIGH] CWE-276 Access to Unix domain socket can lead to privileges escalation in Cilium
Access to Unix domain socket can lead to privileges escalation in Cilium
### Impact
Users with host file system access on a node and the privileges to run as group ID 1000 can gain access to the per node API of Cilium via Unix domain socket on the host where Cilium is running. If a malicious user is able to gain unprivileged access to a user corresponding to this group, then they can leverage
ghsaosv
CVE-2024-42488P3MEDIUM≥ 0, < 1.14.14≥ 1.15.0, < 1.15.82024-08-15
CVE-2024-42488 [MEDIUM] CWE-362 Policy bypass for Host Firewall policy due to race condition in Cilium agent
Policy bypass for Host Firewall policy due to race condition in Cilium agent
### Impact
A race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass.
### Patches
This issue was fixed in https://github.
ghsaosv
CVE-2025-23047P4MEDIUM≥ 1.14.0, < 1.14.19≥ 1.15.0, < 1.15.13+1 more2025-01-22
CVE-2025-23047 [MEDIUM] CWE-200 Cilium has an information leakage via insecure default Hubble UI CORS header
Cilium has an information leakage via insecure default Hubble UI CORS header
### Impact
For users who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart, an insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kuber
ghsaosv
CVE-2026-53935P3MEDIUM≥ 1.19.0, < 1.19.4≥ 1.18.2, < 1.18.10+1 more2026-07-06
CVE-2026-53935 [MEDIUM] CWE-601 CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
### Impact
Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping
ghsa
CVE-2023-30851P4MEDIUM≥ 0, < 1.11.16≥ 1.12.0, < 1.12.9+1 more2023-05-22
CVE-2023-30851 [MEDIUM] CWE-693 Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
### Impact
This issue only impacts users who:
- Have a HTTP policy that applies to multiple `toEndpoints` AND
- Have an allow-all rule in place that affects only one of those endpoints
In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies.
### Patches
This issue has been pa
ghsaosv
CVE-2024-37307P4HIGH≥ 1.13.0, < 1.13.17≥ 1.14.0, < 1.14.12+1 more2024-06-13
CVE-2024-37307 [HIGH] CWE-200 Cilium leaks sensitive information in cilium-bugtool
Cilium leaks sensitive information in cilium-bugtool
### Impact
The output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag set) against Cilium deployments with the Envoy proxy enabled.
Users of the following features are affected:
- [TLS inspection](https://docs.cilium.io/en/stable/security/tls-visibility/#gs-tls-inspection)
- [Ingress with TLS termination](htt
ghsaosv
CVE-2023-29002P4HIGH≥ 1.7.0, ≤ 1.10.0≥ 1.11.0, < 1.11.16+2 more2023-04-19
CVE-2023-29002 [HIGH] CWE-532 Debug mode leaks confidential data in Cilium
Debug mode leaks confidential data in Cilium
### Impact
When run in debug mode, Cilium may log sensitive information.
In particular, Cilium running in debug mode will log the values of headers if they match HTTP network policy rules. This issue affects Cilium versions:
- 1.7.* to 1.10.* inclusive
- 1.11.* before 1.11.16
- 1.12.* before 1.12.9
- 1.13.* before 1.13.2
In addition, Cilium 1.12.* before 1.12.9 and 1.13.*
ghsaosv
CVE-2024-28860P4HIGH≥ 1.4.0, < 1.13.14≥ 1.14.0, < 1.14.9+1 more2024-03-28
CVE-2024-28860 [HIGH] CWE-326 Cilium has insecure IPsec transport encryption
Cilium has insecure IPsec transport encryption
### Impact
Users of [IPsec transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-ipsec/) in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective.
In particular, Cilium is vulnerable to the following attacks by a man-in-the-middle attacker:
- Chosen plaintext attacks
- Key recovery attacks
- R
ghsaosv
CVE-2024-52529P4MEDIUM≥ 1.16.0, < 1.16.42024-11-25
CVE-2024-52529 [MEDIUM] CWE-755 Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges
Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges
### Impact
For users with the following configuration:
* An allow policy that selects a [Layer 3 identity](https://docs.cilium.io/en/v1.14/security/policy/language/#layer-3-examples) and a [port range](https://docs.cilium.io/en/stable/security/policy/language/#example-port-ranges) **A
ghsaosv
CVE-2023-34242P4LOW≥ 1.13.0, < 1.13.42023-06-16
CVE-2023-34242 [LOW] CWE-200 Cilium vulnerable to information leakage via incorrect ReferenceGrant handling
Cilium vulnerable to information leakage via incorrect ReferenceGrant handling
### Impact
When the [Gateway API](https://docs.cilium.io/en/v1.13/network/servicemesh/gateway-api/gateway-api/) is enabled in Cilium, the absence of a check on the namespace in which a [ReferenceGrant](https://gateway-api.sigs.k8s.io/api-types/referencegrant/) is created could result in Cilium gaining visibili
ghsaosv
1 / 2Next →