CVE-2024-28248High· 7.2▾ TwilightIntermittent HTTP policy bypass
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
Cilium's HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped.
This issue affects:
This issue has been patched in:
There is no workaround for this issue – affected users are strongly encouraged to upgrade.
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @romikps for discovering and reporting this issue, and @sayboras and @jrajahalme for preparing the fix.
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [email protected]. This is a private mailing list for the Cilium internal security team, and your report will be treated as top priority.
github.com/cilium/cilium >= 1.13.9, < 1.13.13github.com/cilium/cilium >= 1.14.0, < 1.14.8github.com/cilium/cilium >= 1.15.0, < 1.15.2Upgrade to a patched release:
github.com/cilium/cilium 1.13.13github.com/cilium/cilium 1.14.8github.com/cilium/cilium 1.15.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
CVE-2024-47825Medium· 4.0Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
CVE-2025-64715Medium· 4.0Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic