Security Advisories for github.com/cilium/cilium in go
Moderate
about 1 month ago
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
go
github.com/cilium/cilium, Ciliumgithub.com/cilium/cilium
Moderate
9 months ago
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
go
github.com/cilium/cilium
Low
10 months ago
Cilium node based network policies may incorrectly allow workload traffic
go
Ciliumgithub.com/cilium/cilium, github.com/cilium/cilium
Low
10 months ago
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
go
github.com/cilium/cilium
Moderate
12 months ago
Cilium has an information leakage via insecure default Hubble UI CORS header
go
github.com/cilium/cilium
Moderate
12 months ago
DoS in Cilium agent DNS proxy from crafted DNS responses
go
github.com/cilium/cilium
Moderate
about 1 year ago
Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges
go
github.com/cilium/cilium
Moderate
about 1 year ago
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
go
github.com/cilium/cilium
Moderate
over 1 year ago
Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API
go
github.com/cilium/cilium
Moderate
over 1 year ago
Gateway API route matching order contradicts specification
go
github.com/cilium/cilium
Moderate
over 1 year ago
Policy bypass for Host Firewall policy due to race condition in Cilium agent
go
github.com/cilium/cilium
High
over 1 year ago
Cilium leaks sensitive information in cilium-bugtool
go
github.com/cilium/cilium
Moderate
almost 2 years ago
Unencrypted traffic between nodes when using WireGuard and L7 policies
go
github.com/cilium/cilium
Moderate
almost 2 years ago
Unencrypted traffic between nodes when using IPsec and L7 policies
go
github.com/cilium/cilium
Moderate
almost 2 years ago
Unencrypted traffic between pods when using Wireguard and an external kvstore
go
github.com/cilium/cilium
Moderate
almost 2 years ago
Unencrypted ingress/health traffic when using Wireguard transparent encryption
go
github.com/cilium/cilium
Moderate
over 2 years ago
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
go
github.com/cilium/cilium
Low
over 2 years ago
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
go
github.com/cilium/cilium
Moderate
over 2 years ago
Kubernetes users may update Pod labels to bypass network policy
go
github.com/cilium/cilium
Low
over 2 years ago
Cilium vulnerable to information leakage via incorrect ReferenceGrant handling
go
github.com/cilium/cilium
Moderate
over 2 years ago
Potential HTTP policy bypass when using header rules in Cilium
go
github.com/cilium/cilium
Moderate
almost 3 years ago
Cilium eBPF filters may be temporarily removed during agent restart
go
github.com/cilium/cilium
Moderate
almost 3 years ago
Potential network policy bypass when routing IPv6 traffic
go
github.com/cilium/cilium
Moderate
almost 3 years ago
cilium-agent container can access the host via `hostPath` mount
go
github.com/cilium/cilium
Moderate
over 3 years ago
Network Policies & (Clusterwide) Cilium Network Policies with namespace label selectors may unexpectedly select pods with maliciously crafted labels
go
github.com/cilium/cilium
Low
over 3 years ago
Cilium host policy bypass in endpoint-routes mode with dual-stack
go
github.com/cilium/cilium
High
over 3 years ago
Access to Unix domain socket can lead to privileges escalation in Cilium
go
github.com/cilium/cilium
Low
over 4 years ago
Network policy may be bypassed by some ICMP Echo Requests
go
github.com/cilium/cilium