CVE-2025-32793Medium· 4.0▾ SunlitIn Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.1%
0.1% → 0.1%
When using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium.
This issue has been patched in https://github.com/cilium/cilium/pull/38592.
This issue affects:
This issue is fixed in:
There is no workaround to this issue.
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @gandro and @pippolo84 for reporting this issue and to @julianwiedmann for the patch.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and your report will be treated as top priority.
github.com/cilium/cilium >= 1.13.0, < 1.15.16github.com/cilium/cilium >= 1.16.0, < 1.16.9github.com/cilium/cilium >= 1.17.0, < 1.17.3Upgrade to a patched release:
github.com/cilium/cilium 1.15.16github.com/cilium/cilium 1.16.9github.com/cilium/cilium 1.17.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
CVE-2024-47825Medium· 4.0Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
CVE-2025-64715Medium· 4.0Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic