VYPR

Bitnami package

cilium

pkg:bitnami/cilium

Vulnerabilities (36)

  • CVE-2026-56743MedJul 15, 2026
    affected >= 1.19.0, < 1.19.5fixed 1.19.5

    Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured w

  • CVE-2026-56742MedJul 15, 2026
    affected < 1.17.17fixed 1.17.17

    Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the Refe

  • CVE-2026-49445CriJul 15, 2026
    affected < 1.17.14fixed 1.17.14

    Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing a local attacker to access Envoy

  • CVE-2026-53935MedJul 7, 2026
    affected < 1.17.16fixed 1.17.16

    Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Servic

  • CVE-2026-41520HigMay 8, 2026
    affected < 1.17.15fixed 1.17.15

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. Thi

  • CVE-2026-33726MedMar 27, 2026
    affected < 1.17.14fixed 1.17.14

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-

  • CVE-2026-26963MedFeb 20, 2026
    affected >= 1.18.0, < 1.18.6fixed 1.18.6

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption are enabled. This issue has been fixed in version

  • CVE-2025-64715MedNov 29, 2025
    affected < 1.16.17fixed 1.16.17

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not attache

  • CVE-2025-32793MedApr 21, 2025
    affected >= 1.13.0, < 1.17.3fixed 1.17.3

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating

  • CVE-2025-30163LowMar 24, 2025
    affected >= 1.16.0, < 1.17.2fixed 1.17.2

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of n

  • CVE-2025-30162LowMar 24, 2025
    affected >= 1.15.0, < 1.17.2fixed 1.17.2

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a

  • CVE-2025-23047MedJan 22, 2025
    affected >= 1.14.0, < 1.16.5fixed 1.16.5

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-Control-Allow-Origin` header value could lead to sensitive data exposure for users of Cilium versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 t

  • CVE-2025-23028MedJan 22, 2025
    affected >= 1.15.4, < 1.16.5fixed 1.16.5

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cilium is configured to proxy DNS

  • CVE-2024-52529MedNov 25, 2024
    affected >= 1.16.0, < 1.16.4fixed 1.16.4

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects a specific port within the fi

  • CVE-2024-47825MedOct 21, 2024
    affected >= 1.15.4, < 1.16.0fixed 1.16.0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 and 1.15.10, a policy rule denying a prefix that is broader than `/32` may be ignored if there is a policy rule referencing a more n

  • CVE-2024-42486MedAug 16, 2024
    affected >= 1.15.0, < 1.16.1fixed 1.16.1

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could le

  • CVE-2024-42488MedAug 15, 2024
    affected >= 1.15.4, < 1.16.0fixed 1.16.0

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent can cause the agent to ignore labels that should be applied to a node. This could in turn cause CiliumClusterwideN

  • CVE-2024-42487MedAug 15, 2024
    affected >= 1.15.0, < 1.16.1fixed 1.16.1

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification.

  • CVE-2024-37307HigJun 13, 2024
    affected >= 1.15.4, < 1.15.6fixed 1.15.6

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag se

  • CVE-2024-28860HigMar 27, 2024
    affected >= 1.14.0, < 1.14.9fixed 1.14.9

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, Cilium is vulnerable to chosen

Page 1 of 2