github.com/cilium/cilium vulnerabilities
CVEs whose affected-version data names the github.com/cilium/cilium package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
14 CVEsRSS
CVE-2026-56743Medium· 5.4Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
CVE-2026-53935Medium· 6.9CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2025-64715Medium· 4.0Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
CVE-2025-30162Low· 3.2Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
CVE-2024-47825Medium· 4.0Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
Intermittent HTTP policy bypass
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-41332Low· 3.5Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
CVE-2023-30851Medium· 5.3Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
CVE-2023-27593Medium· 4.4cilium-agent container can access the host via `hostPath` mount
cilium-agent container can access the host via `hostPath` mount
CVE-2022-29178High· 8.8Access to Unix domain socket can lead to privileges escalation in Cilium
Access to Unix domain socket can lead to privileges escalation in Cilium