Github.Com Cilium Cilium vulnerabilities
36 known vulnerabilities affecting github.com/cilium_cilium.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW4
Vulnerabilities
Page 2 of 2
CVE-2025-23028P4MEDIUM≥ 1.14.0, < 1.14.18≥ 1.15.0, < 1.15.12+1 more2025-01-22
CVE-2025-23028 [MEDIUM] CWE-770 DoS in Cilium agent DNS proxy from crafted DNS responses
DoS in Cilium agent DNS proxy from crafted DNS responses
### Impact
In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacker can crash Cilium agents by sending a crafted DNS response to workloads from outside the cluster.
For traffic that is allowed but without using DNS-based policy, the dataplane will continue to pass traffic as configured at the time of the DoS. For workload
ghsaosv
CVE-2025-64715P4MEDIUM≥ 1.18.0, < 1.18.4≥ 0, < 1.16.172025-12-01
CVE-2025-64715 [MEDIUM] CWE-284 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
### Impact
`CiliumNetworkPolicy`s which use `egress.toGroups.aws.securityGroupsIds` to reference AWS security group IDs that do not exist or are not attached to any network interface may unintentionally allow broader outbound access than intended by the policy authors. In such cases, the toC
ghsaosv
CVE-2024-28249P4MEDIUM≥ 0, < 1.13.13≥ 1.14.0, < 1.14.8+1 more2024-03-18
CVE-2024-28249 [MEDIUM] CWE-311 Unencrypted traffic between nodes when using IPsec and L7 policies
Unencrypted traffic between nodes when using IPsec and L7 policies
### Impact
In Cilium clusters with IPsec enabled and traffic matching Layer 7 policies:
- Traffic that should be IPsec-encrypted between a node's Envoy proxy and pods on other nodes is sent unencrypted
- Traffic that should be IPsec-encrypted between a node's DNS proxy and pods on other nodes is sent unencrypted
**Note:** For cl
ghsaosv
CVE-2024-28250P4MEDIUM≥ 1.14.0, < 1.14.8≥ 1.15.0, < 1.15.22024-03-18
CVE-2024-28250 [MEDIUM] CWE-311 Unencrypted traffic between nodes when using WireGuard and L7 policies
Unencrypted traffic between nodes when using WireGuard and L7 policies
### Impact
In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies:
- Traffic that should be WireGuard-encrypted is sent unencrypted between a node's Envoy proxy and pods on other nodes.
- Traffic that should be WireGuard-encrypted is sent unencrypted between a node's DNS proxy and pods on other no
ghsaosv
CVE-2026-56743P4MEDIUM≥ 1.19.0, < 1.19.52026-09-03
CVE-2026-56743 [MEDIUM] CWE-863 Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
### Impact
Standard Kubernetes `NetworkPolicy` specifications using CIDR-based `ipBlock` rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule under
ghsa
CVE-2023-27593P4MEDIUM≥ 0, < 1.11.15≥ 1.12.0, < 1.12.8+1 more2023-03-17
CVE-2023-27593 [MEDIUM] CWE-276 cilium-agent container can access the host via `hostPath` mount
cilium-agent container can access the host via `hostPath` mount
### Impact
An attacker with access to a Cilium agent pod can write to `/opt/cni/bin` due to a `hostPath` mount of that directory in the agent pod. By replacing the CNI binary with their own malicious binary and waiting for the creation of a new pod on the node, the attacker can gain access to the underlying node.
### Patches
The issue
ghsaosv
CVE-2024-25630P4MEDIUM≥ 1.14.0, < 1.14.72024-02-20
CVE-2024-25630 [MEDIUM] CWE-311 Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
### Impact
For Cilium users who are using CRDs to store Cilium state (the default configuration) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), responses from pods to the Ingress and health endpoints are not encrypted. Traffic f
ghsaosv
CVE-2024-25631P4MEDIUM≥ 1.14.0, < 1.14.72024-02-20
CVE-2024-25631 [MEDIUM] CWE-311 Unencrypted traffic between pods when using Wireguard and an external kvstore
Unencrypted traffic between pods when using Wireguard and an external kvstore
### Impact
For Cilium users who have enabled [an external kvstore](https://docs.cilium.io/en/stable/installation/k8s-install-external-etcd/#when-do-i-need-to-use-a-kvstore) and [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg), traffic be
ghsaosv
CVE-2026-26963P4MEDIUM≥ 1.18.0, < 1.18.62026-02-19
CVE-2026-26963 [MEDIUM] CWE-863 Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
### Impact
[Host Policies](https://docs.cilium.io/en/stable/security/policy/language/#host-policies) will incorrectly permit traffic from Pods on other nodes when all of the following configurations are enabled:
* [Native Routing](https://docs.cili
ghsaosv
CVE-2024-42487P4MEDIUM≥ 1.16.0, < 1.16.1≥ 1.15.0, < 1.15.82024-08-15
CVE-2024-42487 [MEDIUM] CWE-113 Gateway API route matching order contradicts specification
Gateway API route matching order contradicts specification
### Impact
Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, request headers are matched before request methods, when the specification describes that the request methods must be respected before headers are matched ([HTTPRouteRule](https://gateway-api.sigs.k8s.io/r
ghsaosv
CVE-2026-33726P4MEDIUM≥ 0, < 1.17.14≥ 1.18.0, < 1.18.8+1 more2026-03-26
CVE-2026-33726 [MEDIUM] CWE-284 Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
### Impact
Ingress [Network Policies](https://docs.cilium.io/en/stable/network/kubernetes/policy/#network-policy) are not enforced for traffic from pods to L7 Services ([Envoy](https://docs.cilium.io/en/stable/network/servicemesh/l7-traffic-management), GAMMA) with a local backend on the same node, when [Per-Endpoint
ghsaosv
CVE-2025-30163P4LOW≥ 1.16.0, < 1.16.82025-03-24
CVE-2025-30163 [LOW] CWE-863 Cilium node based network policies may incorrectly allow workload traffic
Cilium node based network policies may incorrectly allow workload traffic
### Impact
[Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is di
ghsaosv
CVE-2026-41520P4HIGH≥ 0, < 1.17.15≥ 1.18.0, < 1.18.9+1 more2026-04-25
CVE-2026-41520 [HIGH] CWE-200 Cillium exposes sensitive information included in the cilium-bugtool debug archive
Cillium exposes sensitive information included in the cilium-bugtool debug archive
### Impact
The output of `cilium-bugtool` can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled.
Users of [WireGuard Transparent Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/) are affected.
The sensitive data
ghsa
CVE-2025-30162P4LOW≥ 1.16.0, < 1.16.8≥ 1.17.0, < 1.17.2+1 more2025-03-24
CVE-2025-30162 [LOW] CWE-863 Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
### Impact
For Cilium users who:
- Use Gateway API for Ingress for some services **AND**
- Use [LB-IPAM](https://docs.cilium.io/en/stable/network/lb-ipam/) or BGP for LB Service implementation **AND**
- Use network policies to block egress traffic f
ghsaosv
CVE-2025-32793P4MEDIUM≥ 1.13.0, < 1.15.16≥ 1.16.0, < 1.16.9+1 more2025-04-21
CVE-2025-32793 [MEDIUM] CWE-319 In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
### Impact
When using [Wireguard transparent encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/#encryption-wg) in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a ra
ghsaosv
CVE-2023-41332P4LOW≥ 1.14.0, < 1.14.2≥ 0, < 1.12.14+1 more2023-09-27
CVE-2023-41332 [LOW] CWE-755 Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
### Impact
In Cilium clusters where Cilium's Layer 7 proxy has been disabled, creating workloads with
- `policy.cilium.io/proxy-visibility` annotations (in Cilium >= v1.13)
- `io.cilium.proxy-visibility` annotations (in Cilium <= v1.12)
causes the Cilium agent to segfault on the node to which the workload is assig
ghsaosv
← Previous2 / 2