cbcvebase.

Github.Com Cilium Cilium vulnerabilities

36 known vulnerabilities affecting github.com/cilium_cilium.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW4

Vulnerabilities

Page 2 of 2
CVE-2025-23028P4MEDIUM≥ 1.14.0, < 1.14.18≥ 1.15.0, < 1.15.12+1 more2025-01-22
CVE-2025-23028 [MEDIUM] CWE-770 DoS in Cilium agent DNS proxy from crafted DNS responses DoS in Cilium agent DNS proxy from crafted DNS responses ### Impact In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacker can crash Cilium agents by sending a crafted DNS response to workloads from outside the cluster. For traffic that is allowed but without using DNS-based policy, the dataplane will continue to pass traffic as configured at the time of the DoS. For workload
ghsaosv
CVE-2025-64715P4MEDIUM≥ 1.18.0, < 1.18.4≥ 0, < 1.16.172025-12-01
CVE-2025-64715 [MEDIUM] CWE-284 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic ### Impact `CiliumNetworkPolicy`s which use `egress.toGroups.aws.securityGroupsIds` to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toC
ghsaosv
CVE-2024-28249P4MEDIUM≥ 0, < 1.13.13≥ 1.14.0, < 1.14.8+1 more2024-03-18
CVE-2024-28249 [MEDIUM] CWE-311 Unencrypted traffic between nodes when using IPsec and L7 policies Unencrypted traffic between nodes when using IPsec and L7 policies ### Impact In Cilium clusters with IPsec enabled and traffic matching Layer 7 policies: - Traffic that should be IPsec-encrypted between a node's Envoy proxy and pods on other nodes is sent unencrypted - Traffic that should be IPsec-encrypted between a node's DNS proxy and pods on other nodes is sent unencrypted **Note:** For cl
ghsaosv
CVE-2024-28250P4MEDIUM≥ 1.14.0, < 1.14.8≥ 1.15.0, < 1.15.22024-03-18
CVE-2024-28250 [MEDIUM] CWE-311 Unencrypted traffic between nodes when using WireGuard and L7 policies Unencrypted traffic between nodes when using WireGuard and L7 policies ### Impact In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies: - Traffic that should be WireGuard-encrypted is sent unencrypted between a node's Envoy proxy and pods on other nodes. - Traffic that should be WireGuard-encrypted is sent unencrypted between a node's DNS proxy and pods on other no
ghsaosv
CVE-2026-56743P4MEDIUM≥ 1.19.0, < 1.19.52026-09-03
CVE-2026-56743 [MEDIUM] CWE-863 Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match ### Impact Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under
ghsa
CVE-2023-27593P4MEDIUM≥ 0, < 1.11.15≥ 1.12.0, < 1.12.8+1 more2023-03-17
CVE-2023-27593 [MEDIUM] CWE-276 cilium-agent container can access the host via `hostPath` mount cilium-agent container can access the host via `hostPath` mount ### Impact An attacker with access to a Cilium agent pod can write to `/opt/cni/bin` due to a `hostPath` mount of that directory in the agent pod. By replacing the CNI binary with their own malicious binary and waiting for the creation of a new pod on the node, the attacker can gain access to the underlying node. ### Patches The issue
ghsaosv
CVE-2024-25630P4MEDIUM≥ 1.14.0, < 1.14.72024-02-20
CVE-2024-25630 [MEDIUM] CWE-311 Unencrypted ingress/health traffic when using Wireguard transparent encryption Unencrypted ingress/health traffic when using Wireguard transparent encryption ### Impact For Cilium users who are using CRDs to store Cilium state (the default configuration) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), responses from pods to the Ingress and health endpoints are not encrypted. Traffic f
ghsaosv
CVE-2024-25631P4MEDIUM≥ 1.14.0, < 1.14.72024-02-20
CVE-2024-25631 [MEDIUM] CWE-311 Unencrypted traffic between pods when using Wireguard and an external kvstore Unencrypted traffic between pods when using Wireguard and an external kvstore ### Impact For Cilium users who have enabled [an external kvstore](https://docs.cilium.io/en/stable/installation/k8s-install-external-etcd/#when-do-i-need-to-use-a-kvstore) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), traffic be
ghsaosv
CVE-2026-26963P4MEDIUM≥ 1.18.0, < 1.18.62026-02-19
CVE-2026-26963 [MEDIUM] CWE-863 Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled ### Impact [Host Policies](https://docs.cilium.io/en/stable/security/policy/language/#host-policies) will incorrectly permit traffic from Pods on other nodes when all of the following configurations are enabled: * [Native Routing](https://docs.cili
ghsaosv
CVE-2024-42487P4MEDIUM≥ 1.16.0, < 1.16.1≥ 1.15.0, < 1.15.82024-08-15
CVE-2024-42487 [MEDIUM] CWE-113 Gateway API route matching order contradicts specification Gateway API route matching order contradicts specification ### Impact Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, request headers are matched before request methods, when the specification describes that the request methods must be respected before headers are matched ([HTTPRouteRule](https://gateway-api.sigs.k8s.io/r
ghsaosv
CVE-2026-33726P4MEDIUM≥ 0, < 1.17.14≥ 1.18.0, < 1.18.8+1 more2026-03-26
CVE-2026-33726 [MEDIUM] CWE-284 Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic ### Impact Ingress [Network Policies](https://docs.cilium.io/en/stable/network/kubernetes/policy/#network-policy) are not enforced for traffic from pods to L7 Services ([Envoy](https://docs.cilium.io/en/stable/network/servicemesh/l7-traffic-management), GAMMA) with a local backend on the same node, when [Per-Endpoint
ghsaosv
CVE-2025-30163P4LOW≥ 1.16.0, < 1.16.82025-03-24
CVE-2025-30163 [LOW] CWE-863 Cilium node based network policies may incorrectly allow workload traffic Cilium node based network policies may incorrectly allow workload traffic ### Impact [Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is di
ghsaosv
CVE-2026-41520P4HIGH≥ 0, < 1.17.15≥ 1.18.0, < 1.18.9+1 more2026-04-25
CVE-2026-41520 [HIGH] CWE-200 Cillium exposes sensitive information included in the cilium-bugtool debug archive Cillium exposes sensitive information included in the cilium-bugtool debug archive ### Impact The output of `cilium-bugtool` can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. Users of [WireGuard Transparent Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/) are affected. The sensitive data
ghsa
CVE-2025-30162P4LOW≥ 1.16.0, < 1.16.8≥ 1.17.0, < 1.17.2+1 more2025-03-24
CVE-2025-30162 [LOW] CWE-863 Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers ### Impact For Cilium users who: - Use Gateway API for Ingress for some services **AND** - Use [LB-IPAM](https://docs.cilium.io/en/stable/network/lb-ipam/) or BGP for LB Service implementation **AND** - Use network policies to block egress traffic f
ghsaosv
CVE-2025-32793P4MEDIUM≥ 1.13.0, < 1.15.16≥ 1.16.0, < 1.16.9+1 more2025-04-21
CVE-2025-32793 [MEDIUM] CWE-319 In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters ### Impact When using [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg) in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a ra
ghsaosv
CVE-2023-41332P4LOW≥ 1.14.0, < 1.14.2≥ 0, < 1.12.14+1 more2023-09-27
CVE-2023-41332 [LOW] CWE-755 Specific Cilium configurations vulnerable to DoS via Kubernetes annotations Specific Cilium configurations vulnerable to DoS via Kubernetes annotations ### Impact In Cilium clusters where Cilium's Layer 7 proxy has been disabled, creating workloads with - `policy.cilium.io/proxy-visibility` annotations (in Cilium >= v1.13) - `io.cilium.proxy-visibility` annotations (in Cilium <= v1.12) causes the Cilium agent to segfault on the node to which the workload is assig
ghsaosv
Github.Com Cilium Cilium vulnerabilities | cvebase