📦 Cilium

by Cilium

🔍 What is Cilium?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-37307

HIGH CVSS 7.9 Jun 13, 2024

CVE-2024-37307 is a sensitive data exposure vulnerability in Cilium's cilium-bugtool debugging utility. When run with the --envoy-dump flag against deployments with Envoy proxy enabled, the tool can e...

CVE-2024-28860

HIGH CVSS 8.0 Mar 27, 2024

CVE-2024-28860 is a cryptographic vulnerability in Cilium's IPsec transparent encryption that allows man-in-the-middle attackers to perform chosen plaintext, key recovery, and replay attacks when mult...

CVE-2024-28248

HIGH CVSS 7.2 Mar 18, 2024

CVE-2024-28248 is a security vulnerability in Cilium's HTTP policy enforcement where HTTP traffic that should be blocked according to configured policies is intermittently allowed through. This affect...

CVE-2023-39347

HIGH CVSS 7.6 Sep 27, 2023

This CVE allows attackers with Kubernetes API access to bypass Cilium network policies by updating pod labels with non-existent construct names. It affects Cilium users who rely on network policies fo...

CVE-2022-29179

HIGH CVSS 7.5 May 20, 2022

This CVE allows an attacker who has already escaped a container running as root to escalate privileges to Kubernetes cluster admin using Cilium's service account. It affects Cilium installations prior...

CVE-2025-64715

MEDIUM CVSS 4.0 Nov 29, 2025

This CVE describes a misconfiguration vulnerability in Cilium where AWS security group IDs referenced in CiliumNetworkPolicies that don't exist or aren't attached to network interfaces may cause broad...

CVE-2025-23047

MEDIUM CVSS 6.5 Jan 22, 2025

CVE-2025-23047 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Cilium's Hubble UI that allows malicious websites to access sensitive Kubernetes cluster configuration data. ...

CVE-2025-23028

MEDIUM CVSS 5.3 Jan 22, 2025

A denial of service vulnerability in Cilium allows attackers to crash Cilium agents by sending crafted DNS responses to workloads from outside the cluster. This affects Kubernetes clusters running vul...

CVE-2024-47825

MEDIUM CVSS 4.0 Oct 21, 2024

Cilium versions 1.14.0 through 1.14.15 and 1.15.0 through 1.15.9 have a policy bypass vulnerability where certain CIDR-based deny rules may be ignored when conflicting with specific allow rules. This ...

CVE-2024-42486

MEDIUM CVSS 5.4 Aug 16, 2024

A vulnerability in Cilium's GatewayAPI controller fails to properly propagate ReferenceGrant changes, allowing Gateway resources to retain access to secrets longer than intended or Routes to forward t...

CVE-2024-42488

MEDIUM CVSS 6.8 Aug 15, 2024

A race condition in Cilium agent versions before 1.14.14 and 1.15.8 can cause node labels to be ignored, potentially allowing CiliumClusterwideNetworkPolicies to be bypassed. This affects users runnin...