VulnSea

github.com/cilium/cilium vulnerabilities

CVEs whose affected-version data names the github.com/cilium/cilium package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-56743Medium· 5.4
2w ago

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Sunlitcilium · github.com/cilium/ciliumEPSS 0.25%via GHSA
CVE-2026-53935Medium· 6.9
2mo ago

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

Sunlitcilium · github.com/cilium/ciliumEPSS 0.34%via GHSA
CVE-2026-49445Critical· 9.2
2mo ago

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Midnightcilium · github.com/cilium/ciliumEPSS 0.17%via GHSA
CVE-2025-64715Medium· 4.0
9mo ago

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

Sunlitcilium · github.com/cilium/ciliumEPSS 0.17%via OSV
CVE-2025-32793Medium· 4.0
1y ago

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

Sunlitcilium · github.com/cilium/ciliumEPSS 0.14%via OSV
CVE-2025-30162Low· 3.2
1y ago

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

Sunlitcilium · github.com/cilium/ciliumEPSS 0.22%via OSV
CVE-2024-47825Medium· 4.0
1y ago

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

Sunlitcilium · github.com/cilium/ciliumEPSS 0.40%via OSV
CVE-2024-28248High· 7.2
2y ago

Intermittent HTTP policy bypass

Intermittent HTTP policy bypass

Twilightcilium · github.com/cilium/ciliumEPSS 0.62%via OSV
CVE-2024-25630Medium· 6.1
2y ago

Unencrypted ingress/health traffic when using Wireguard transparent encryption

Unencrypted ingress/health traffic when using Wireguard transparent encryption

Sunlitcilium · github.com/cilium/ciliumEPSS 0.18%via OSV
CVE-2023-41333Medium· 6.9
2y ago

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

Sunlitcilium · github.com/cilium/ciliumEPSS 0.41%via OSV
CVE-2023-41332Low· 3.5
2y ago

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

Sunlitcilium · github.com/cilium/ciliumEPSS 0.45%via OSV
CVE-2023-30851Medium· 5.3
3y ago

Potential HTTP policy bypass when using header rules in Cilium

Potential HTTP policy bypass when using header rules in Cilium

Sunlitcilium · github.com/cilium/ciliumEPSS 0.66%via OSV
CVE-2023-27593Medium· 4.4
3y ago

cilium-agent container can access the host via `hostPath` mount

cilium-agent container can access the host via `hostPath` mount

Sunlitcilium · github.com/cilium/ciliumEPSS 0.22%via OSV
CVE-2022-29178High· 8.8
4y ago

Access to Unix domain socket can lead to privileges escalation in Cilium

Access to Unix domain socket can lead to privileges escalation in Cilium

Twilightcilium · github.com/cilium/ciliumEPSS 0.28%via OSV
github.com/cilium/cilium vulnerabilities (CVEs) · VulnSea