vciy

CVEs we hold for Cilium

Records whose assigning authority named Cilium as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-56743Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured…cilium
CVE-2026-56742Cilium: Namespaced HTTPRoutes can redirect traffic to other namespacescilium
CVE-2026-53935CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service…cilium
CVE-2026-49445Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket accesscilium
CVE-2026-41520Cillium exposes sensitive information included in the cilium-bugtool debug archivecilium
CVE-2026-33726Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node trafficcilium
CVE-2026-26963Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabledcilium
CVE-2026-10722cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflowcilium ebpf
CVE-2025-64715Cilium with misconfigured toGroups in policies can lead to unrestricted egress trafficcilium
CVE-2025-48056Hubble CLI vulnerable to character injectioncilium hubble
CVE-2025-32793Cilium packets from terminating endpoints may not be encrypted in Wireguard-enabled clusterscilium
CVE-2025-30163Node based network policies may incorrectly allow workload trafficcilium
CVE-2025-30162East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancerscilium
CVE-2025-23047Cilium vulnerable to information leakage via insecure default Hubble UI CORS headercilium
CVE-2025-23028DoS in Cilium agent DNS proxy from crafted DNS responsescilium
CVE-2024-52529Layer 7 policy enforcement may not occur in policies with wildcarded port ranges in Ciliumcilium
CVE-2024-47825CIDR deny policies may not take effect when a more narrow CIDR allow is presentcilium
CVE-2024-42488Cilium agent's race condition may lead to policy bypass for Host Firewall policycilium
CVE-2024-42487Cilium's Gateway API route matching order contradicts specificationcilium
CVE-2024-42486Cilium vulnerable to information leakage via incorrect ReferenceGrant update logic in Gateway APIcilium
CVE-2024-37307Cilium leaks sensitive information in cilium-bugtoolcilium
CVE-2024-28860Insecure IPsec transport encryption in Ciliumcilium
CVE-2024-28250Cilium has possible unencrypted traffic between nodes when using WireGuard and L7 policiescilium
CVE-2024-28249Cilium has possible unencrypted traffic between nodes when using IPsec and L7 policiescilium
CVE-2024-28248Cilium intermittent HTTP policy bypasscilium
CVE-2024-25631Unencrypted traffic between pods when using Wireguard and an external kvstorecilium
CVE-2024-25630Cilium has unencrypted ingress/health traffic when using Wireguard transparent encryptioncilium
CVE-2023-41333Bypass of namespace restrictions in CiliumNetworkPolicycilium
CVE-2023-41332Denial of service via Kubernetes annotations in specific Cilium configurationscilium
CVE-2023-39347Cilium NetworkPolicy bypass via pod labelscilium
CVE-2023-34242Cilium vulnerable to information leakage via incorrect ReferenceGrant handlingcilium
CVE-2023-30851Potential HTTP policy bypass when using header rules in Ciliumcilium
CVE-2023-29002Debug mode leaks confidential data in Ciliumcilium
CVE-2023-28114`cilium-cli` disables etcd authorization for clustermesh clusterscilium-cli
CVE-2023-27595Cilium eBPF filters may be temporarily removed during agent restartcilium
CVE-2023-27594Cilium vulnerable to potential network policy bypass when routing IPv6 trafficcilium
CVE-2023-27593cilium-agent container can access the host via `hostPath` mountcilium
CVE-2022-29179Improper Privilege Management in Ciliumcilium
CVE-2022-29178Incorrect Default Permissions in Ciliumcilium

39 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.