CVE-2026-56743
- EPSS 0.16%
- Veröffentlicht 15.07.2026 19:15:30
- Zuletzt bearbeitet 17.07.2026 17:29:02
Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow ru...
CVE-2026-56742
- EPSS 0.17%
- Veröffentlicht 15.07.2026 19:14:07
- Zuletzt bearbeitet 17.07.2026 17:48:48
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any...
CVE-2026-49445
- EPSS 0.13%
- Veröffentlicht 15.07.2026 19:11:55
- Zuletzt bearbeitet 17.07.2026 17:50:17
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a ...
CVE-2026-53935
- EPSS 0.21%
- Veröffentlicht 07.07.2026 20:44:54
- Zuletzt bearbeitet 10.07.2026 17:56:00
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabli...
CVE-2026-41520
- EPSS 0.08%
- Veröffentlicht 08.05.2026 22:01:08
- Zuletzt bearbeitet 18.05.2026 15:12:53
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with Wir...
CVE-2026-33726
- EPSS 0.24%
- Veröffentlicht 27.03.2026 00:23:21
- Zuletzt bearbeitet 01.04.2026 15:53:30
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backe...
CVE-2026-26963
- EPSS 0.13%
- Veröffentlicht 19.02.2026 23:38:36
- Zuletzt bearbeitet 20.02.2026 20:12:51
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This is...
CVE-2025-64715
- EPSS 0.17%
- Veröffentlicht 29.11.2025 00:11:26
- Zuletzt bearbeitet 04.12.2025 20:38:45
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that d...
- EPSS 0.13%
- Veröffentlicht 21.04.2025 15:34:14
- Zuletzt bearbeitet 03.09.2025 17:16:40
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets tha...
CVE-2025-30163
- EPSS 0.21%
- Veröffentlicht 24.03.2025 18:46:35
- Zuletzt bearbeitet 04.09.2025 15:51:32
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNode...