cbcvebase.

Github.Com Cilium Cilium vulnerabilities

36 known vulnerabilities affecting github.com/cilium_cilium.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW4

Vulnerabilities

Page 1 of 2
CVE-2023-27595P3MEDIUM≥ 1.13.0, < 1.13.12023-03-17
CVE-2023-27595 [MEDIUM] CWE-755 Cilium eBPF filters may be temporarily removed during agent restart Cilium eBPF filters may be temporarily removed during agent restart ### Impact When Cilium is started, there is a short period when Cilium eBPF programs are not attached to the host. During this period, the host does not implement any of Cilium's featureset. This can cause disruption to newly established connections during this period due to the lack of Load Balancing, or can cause Network Polic
ghsaosv
CVE-2024-47825P3MEDIUM≥ 1.15.0, < 1.15.10≥ 1.14.0, < 1.14.162024-10-21
CVE-2024-47825 [MEDIUM] CWE-1038 Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present ### Impact A policy rule denying a prefix that is broader than /32 may be ignored if there is - A policy rule referencing a more narrow prefix (`CIDRSet` or `toFQDN`) **and** - This narrower policy rule specifies either `enableDefaultDeny: false` or `- toEntities: all` Note that a rul
ghsaosv
CVE-2026-56742P3MEDIUM≥ 0, < 1.17.17≥ 1.19.0, < 1.19.52026-09-24
CVE-2026-56742 [MEDIUM] CWE-862 Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces ### Impact In Cilium clusters using [Gateway API](https://docs.cilium.io/en/stable/network/servicemesh/gateway-api/gateway-api/), users with permissions to create or update namespaced HTTPRoutes can mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API funct
ghsa
CVE-2023-39347P3MEDIUM≥ 1.13.0, < 1.13.7≥ 1.14.0, < 1.14.2+1 more2023-09-26
CVE-2023-39347 [MEDIUM] CWE-345 Kubernetes users may update Pod labels to bypass network policy Kubernetes users may update Pod labels to bypass network policy ### Impact An attacker with the ability to update pod labels can cause Cilium to apply incorrect network policies. This issue arises due to the fact that on pod update, Cilium incorrectly uses user-provided pod labels to select the policies which apply to the workload in question. This can affect: * Cilium network policies that use t
ghsaosv
CVE-2026-49445P3CRITICAL≥ 1.19.0, < 1.19.2≥ 1.18.0, < 1.18.8+1 more2026-07-06
CVE-2026-49445 [CRITICAL] CWE-862 Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access ### Impact When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Dependin
ghsa
CVE-2023-27594P3MEDIUM≥ 0, < 1.11.15≥ 1.12.0, < 1.12.8+1 more2023-03-17
CVE-2023-27594 [MEDIUM] CWE-285 Potential network policy bypass when routing IPv6 traffic Potential network policy bypass when routing IPv6 traffic ## Impact Under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from the host on which Cilium is running. As a consequence, network policies for that cluster might be bypassed, depending on the specific network policies enabled. Only IPv6 traffic is impacted by this
ghsaosv
CVE-2024-28248P3HIGH≥ 1.13.9, < 1.13.13≥ 1.14.0, < 1.14.8+1 more2024-03-18
CVE-2024-28248 [HIGH] CWE-693 Intermittent HTTP policy bypass Intermittent HTTP policy bypass ### Impact Cilium's [HTTP policies](https://docs.cilium.io/en/stable/security/policy/language/#http) are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped. ### Patches This issue affects: * Cilium v1.13 between v1.13.9 and v1.13.12 inclusive * Cilium v1.14 between v1.14.0 and v1.14.7
ghsaosv
CVE-2024-42486P3MEDIUM≥ 1.16.0, < 1.16.1≥ 1.15.0, < 1.15.82024-08-16
CVE-2024-42486 [MEDIUM] CWE-200 Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API ### Impact Due to ReferenceGrant changes not being immediately propagated in Cilium's GatewayAPI controller, Gateway resources are able to access secrets in other namespaces after the associated ReferenceGrant has been revoked. This can lead to Gateways continuing to establish sessions using secrets t
ghsaosv
CVE-2023-41333P3MEDIUM≥ 1.14.0, < 1.14.2≥ 1.13.0, < 1.13.7+1 more2023-09-27
CVE-2023-41333 [MEDIUM] CWE-306 Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy ### Impact An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium cluster, potentially bypassing policy enforcement in other namespaces. By using a crafted `endpointSelector` that uses the `DoesNotExist` operator on t
ghsaosv
CVE-2022-29179P3HIGH≥ 1.11.0, < 1.11.5≥ 1.10.0, < 1.10.11+1 more2022-05-24
CVE-2022-29179 [HIGH] CWE-269 Improper Privilege Management in Cilium Improper Privilege Management in Cilium ### Impact If an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can leverage Cilium's Kubernetes service account to gain access to cluster privileges that are more permissive than what is minimally required to operate Cilium. In affected releases, this service account had access to modify and delete `Pod`
ghsaosv
CVE-2022-29178P3HIGH≥ 1.11.0, < 1.11.5≥ 1.10.0, < 1.10.11+1 more2022-05-24
CVE-2022-29178 [HIGH] CWE-276 Access to Unix domain socket can lead to privileges escalation in Cilium Access to Unix domain socket can lead to privileges escalation in Cilium ### Impact Users with host file system access on a node and the privileges to run as group ID 1000 can gain access to the per node API of Cilium via Unix domain socket on the host where Cilium is running. If a malicious user is able to gain unprivileged access to a user corresponding to this group, then they can leverage
ghsaosv
CVE-2024-42488P3MEDIUM≥ 0, < 1.14.14≥ 1.15.0, < 1.15.82024-08-15
CVE-2024-42488 [MEDIUM] CWE-362 Policy bypass for Host Firewall policy due to race condition in Cilium agent Policy bypass for Host Firewall policy due to race condition in Cilium agent ### Impact A race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideNetworkPolicies intended for nodes with the ignored label to not apply, leading to policy bypass. ### Patches This issue was fixed in https://github.
ghsaosv
CVE-2025-23047P4MEDIUM≥ 1.14.0, < 1.14.19≥ 1.15.0, < 1.15.13+1 more2025-01-22
CVE-2025-23047 [MEDIUM] CWE-200 Cilium has an information leakage via insecure default Hubble UI CORS header Cilium has an information leakage via insecure default Hubble UI CORS header ### Impact For users who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart, an insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kuber
ghsaosv
CVE-2026-53935P3MEDIUM≥ 1.19.0, < 1.19.4≥ 1.18.2, < 1.18.10+1 more2026-07-06
CVE-2026-53935 [MEDIUM] CWE-601 CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation ### Impact Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping
ghsa
CVE-2023-30851P4MEDIUM≥ 0, < 1.11.16≥ 1.12.0, < 1.12.9+1 more2023-05-22
CVE-2023-30851 [MEDIUM] CWE-693 Potential HTTP policy bypass when using header rules in Cilium Potential HTTP policy bypass when using header rules in Cilium ### Impact This issue only impacts users who: - Have a HTTP policy that applies to multiple `toEndpoints` AND - Have an allow-all rule in place that affects only one of those endpoints In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. ### Patches This issue has been pa
ghsaosv
CVE-2024-37307P4HIGH≥ 1.13.0, < 1.13.17≥ 1.14.0, < 1.14.12+1 more2024-06-13
CVE-2024-37307 [HIGH] CWE-200 Cilium leaks sensitive information in cilium-bugtool Cilium leaks sensitive information in cilium-bugtool ### Impact The output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag set) against Cilium deployments with the Envoy proxy enabled. Users of the following features are affected: - [TLS inspection](https://docs.cilium.io/en/stable/security/tls-visibility/#gs-tls-inspection) - [Ingress with TLS termination](htt
ghsaosv
CVE-2023-29002P4HIGH≥ 1.7.0, ≤ 1.10.0≥ 1.11.0, < 1.11.16+2 more2023-04-19
CVE-2023-29002 [HIGH] CWE-532 Debug mode leaks confidential data in Cilium Debug mode leaks confidential data in Cilium ### Impact When run in debug mode, Cilium may log sensitive information. In particular, Cilium running in debug mode will log the values of headers if they match HTTP network policy rules. This issue affects Cilium versions: - 1.7.* to 1.10.* inclusive - 1.11.* before 1.11.16 - 1.12.* before 1.12.9 - 1.13.* before 1.13.2 In addition, Cilium 1.12.* before 1.12.9 and 1.13.*
ghsaosv
CVE-2024-28860P4HIGH≥ 1.4.0, < 1.13.14≥ 1.14.0, < 1.14.9+1 more2024-03-28
CVE-2024-28860 [HIGH] CWE-326 Cilium has insecure IPsec transport encryption Cilium has insecure IPsec transport encryption ### Impact Users of [IPsec transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-ipsec/) in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, Cilium is vulnerable to the following attacks by a man-in-the-middle attacker: - Chosen plaintext attacks - Key recovery attacks - R
ghsaosv
CVE-2024-52529P4MEDIUM≥ 1.16.0, < 1.16.42024-11-25
CVE-2024-52529 [MEDIUM] CWE-755 Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges ### Impact For users with the following configuration: * An allow policy that selects a [Layer 3 identity](https://docs.cilium.io/en/v1.14/security/policy/language/#layer-3-examples) and a [port range](https://docs.cilium.io/en/stable/security/policy/language/#example-port-ranges) **A
ghsaosv
CVE-2023-34242P4LOW≥ 1.13.0, < 1.13.42023-06-16
CVE-2023-34242 [LOW] CWE-200 Cilium vulnerable to information leakage via incorrect ReferenceGrant handling Cilium vulnerable to information leakage via incorrect ReferenceGrant handling ### Impact When the [Gateway API](https://docs.cilium.io/en/v1.13/network/servicemesh/gateway-api/gateway-api/) is enabled in Cilium, the absence of a check on the namespace in which a [ReferenceGrant](https://gateway-api.sigs.k8s.io/api-types/referencegrant/) is created could result in Cilium gaining visibili
ghsaosv
Github.Com Cilium Cilium vulnerabilities | cvebase