CVE-2026-26963
- EPSS 0.01%
- Veröffentlicht 19.02.2026 23:38:36
- Zuletzt bearbeitet 20.02.2026 20:12:51
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This is...
CVE-2025-64715
- EPSS 0.02%
- Veröffentlicht 29.11.2025 00:11:26
- Zuletzt bearbeitet 04.12.2025 20:38:45
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that d...
- EPSS 0.03%
- Veröffentlicht 21.04.2025 15:34:14
- Zuletzt bearbeitet 03.09.2025 17:16:40
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets tha...
CVE-2025-30163
- EPSS 0.05%
- Veröffentlicht 24.03.2025 18:46:35
- Zuletzt bearbeitet 04.09.2025 15:51:32
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNode...
CVE-2025-30162
- EPSS 0.01%
- Veröffentlicht 24.03.2025 18:44:07
- Zuletzt bearbeitet 04.09.2025 15:50:57
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egres...
CVE-2025-23047
- EPSS 0.04%
- Veröffentlicht 22.01.2025 18:15:21
- Zuletzt bearbeitet 03.09.2025 17:17:10
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for users of Cilium versions 1.14.0 through 1.14.7, 1.15.0...
CVE-2025-23028
- EPSS 0.05%
- Veröffentlicht 22.01.2025 17:15:13
- Zuletzt bearbeitet 03.09.2025 17:17:47
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cili...
CVE-2024-52529
- EPSS 0.08%
- Veröffentlicht 25.11.2024 19:15:11
- Zuletzt bearbeitet 03.09.2025 17:18:14
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects...
CVE-2024-47825
- EPSS 0.21%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 19.12.2024 15:59:27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if there is a po...
CVE-2024-42486
- EPSS 0.33%
- Veröffentlicht 16.08.2024 15:15:28
- Zuletzt bearbeitet 03.09.2025 17:18:44
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's Gateway...