CVE-2025-30162
- EPSS 0.22%
- Veröffentlicht 24.03.2025 18:44:07
- Zuletzt bearbeitet 04.09.2025 15:50:57
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egres...
CVE-2025-23047
- EPSS 0.5%
- Veröffentlicht 22.01.2025 18:15:21
- Zuletzt bearbeitet 03.09.2025 17:17:10
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for users of Cilium versions 1.14.0 through 1.14.7, 1.15.0...
CVE-2025-23028
- EPSS 0.43%
- Veröffentlicht 22.01.2025 17:15:13
- Zuletzt bearbeitet 03.09.2025 17:17:47
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cili...
CVE-2024-52529
- EPSS 0.51%
- Veröffentlicht 25.11.2024 19:15:11
- Zuletzt bearbeitet 03.09.2025 17:18:14
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects...
CVE-2024-47825
- EPSS 0.4%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 19.12.2024 15:59:27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if there is a po...
CVE-2024-42486
- EPSS 0.57%
- Veröffentlicht 16.08.2024 15:15:28
- Zuletzt bearbeitet 03.09.2025 17:18:44
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's Gateway...
CVE-2024-42488
- EPSS 0.5%
- Veröffentlicht 15.08.2024 21:15:17
- Zuletzt bearbeitet 27.09.2024 18:49:05
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in...
CVE-2024-42487
- EPSS 0.54%
- Veröffentlicht 15.08.2024 21:15:16
- Zuletzt bearbeitet 30.09.2024 18:31:04
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in t...
CVE-2024-37307
- EPSS 0.18%
- Veröffentlicht 13.06.2024 16:15:11
- Zuletzt bearbeitet 09.01.2025 16:37:54
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (w...
CVE-2024-28860
- EPSS 0.17%
- Veröffentlicht 27.03.2024 19:15:48
- Zuletzt bearbeitet 02.09.2025 16:05:05
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, C...