Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

cilium — Vulnerabilities & Security Advisories 36

All 36 CVE vulnerabilities found in cilium, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations (CWE) associated with the cilium network security and networking platform developed by Isovalent. It aggregates security vulnerabilities and weaknesses identified in the Cilium ecosystem, covering historical data up to the present day. Here, users can track vendor-specific advisories to monitor the security posture of Cilium releases, understand the technical details of specific weakness classes affecting Kubernetes networking, and look up a product's vulnerability history to assess long-term risks. The data is organized to facilitate security research, compliance auditing, and operational risk management for teams relying on Cilium for service mesh, network policy enforcement, and eBPF-based observability. By consolidating these findings, the resource provides a centralized view of known defects, configuration pitfalls, and implementation flaws that may impact the stability or confidentiality of cluster communications. This aggregation supports developers, security engineers, and system administrators in prioritizing patches and mitigating potential threats effectively. The information is derived from publicly available advisories, code analysis, and community-reported issues, ensuring a comprehensive overview of the current threat landscape for this open-source tool. Users are encouraged to cross-reference this data with official Cilium documentation and release notes for the most accurate guidance on remediation steps and version-specific impacts.

Vendor: cilium

CVE ID Title CVSS Severity Published
CVE-2026-56743 Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match CWE-863 5.4 Medium 2026-07-15
CVE-2026-56742 Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces CWE-862 5.9 Medium 2026-07-15
CVE-2026-49445 Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access CWE-732 9.2 Critical 2026-07-15
CVE-2026-53935 CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation CWE-863 6.9 Medium 2026-07-07
CVE-2026-41520 Cillium exposes sensitive information included in the cilium-bugtool debug archive CWE-200 7.9 High 2026-05-08
CVE-2026-33726 Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic CWE-284 5.4 Medium 2026-03-27
CVE-2026-26963 Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled CWE-863 6.1 Medium 2026-02-19
CVE-2025-64715 Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic CWE-284 4.0 Medium 2025-11-29
CVE-2025-32793 Cilium packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters CWE-319 4.0 Medium 2025-04-21
CVE-2025-30163 Node based network policies may incorrectly allow workload traffic CWE-863 3.4 Low 2025-03-24
CVE-2025-30162 East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers CWE-863 3.2 Low 2025-03-24
CVE-2025-23047 Cilium vulnerable to information leakage via insecure default Hubble UI CORS header CWE-200 6.5 Medium 2025-01-22
CVE-2025-23028 DoS in Cilium agent DNS proxy from crafted DNS responses CWE-770 5.3 Medium 2025-01-22
CVE-2024-52529 Layer 7 policy enforcement may not occur in policies with wildcarded port ranges in Cilium CWE-755 5.8 Medium 2024-11-25
CVE-2024-47825 CIDR deny policies may not take effect when a more narrow CIDR allow is present CWE-276 4.0 Medium 2024-10-21
CVE-2024-42486 Cilium vulnerable to information leakage via incorrect ReferenceGrant update logic in Gateway API CWE-200 5.4 Medium 2024-08-16
CVE-2024-42488 Cilium agent's race condition may lead to policy bypass for Host Firewall policy CWE-362 6.8 Medium 2024-08-15
CVE-2024-42487 Cilium's Gateway API route matching order contradicts specification CWE-113 4.0 Medium 2024-08-15
CVE-2024-37307 Cilium leaks sensitive information in cilium-bugtool CWE-200 7.9 High 2024-06-13
CVE-2024-28860 Insecure IPsec transport encryption in Cilium CWE-326 8.0 High 2024-03-27
CVE-2024-28250 Cilium has possible unencrypted traffic between nodes when using WireGuard and L7 policies CWE-311 6.1 Medium 2024-03-18
CVE-2024-28249 Cilium has possible unencrypted traffic between nodes when using IPsec and L7 policies CWE-311 6.1 Medium 2024-03-18
CVE-2024-28248 Cilium intermittent HTTP policy bypass CWE-693 7.2 High 2024-03-18
CVE-2024-25631 Unencrypted traffic between pods when using Wireguard and an external kvstore CWE-311 6.1 Medium 2024-02-20
CVE-2024-25630 Cilium has unencrypted ingress/health traffic when using Wireguard transparent encryption CWE-311 6.1 Medium 2024-02-20
CVE-2023-41332 Denial of service via Kubernetes annotations in specific Cilium configurations CWE-755 3.5 Low 2023-09-26
CVE-2023-41333 Bypass of namespace restrictions in CiliumNetworkPolicy CWE-306 6.9 Medium 2023-09-26
CVE-2023-39347 Cilium NetworkPolicy bypass via pod labels CWE-345 7.6 High 2023-09-26
CVE-2023-34242 Cilium vulnerable to information leakage via incorrect ReferenceGrant handling CWE-200 3.4 Low 2023-06-15
CVE-2023-30851 Potential HTTP policy bypass when using header rules in Cilium CWE-693 2.6 Low 2023-05-25

All 36 known CVE vulnerabilities affecting cilium with full Chinese analysis, references, and POCs where available.