Skip to content
Noroxi

cilium records

37 published records for vendor cilium.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

37 records
  • Cilium eBPF filters may be temporarily removed during agent restart

    CriticalCVSS 9.8No exploitEPSS 1%

    cilium · ciliumMar 17, 2023

  • Cilium NetworkPolicy bypass via pod labels

    CriticalCVSS 9.0No exploitEPSS 1%

    cilium · ciliumSep 27, 2023

  • Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

    HighCVSS 8.9No exploitEPSS 0%

    cilium · ciliumJul 15, 2026

  • Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access

    HighCVSS 8.8No exploitEPSS 0%

    cilium · ciliumJul 15, 2026

  • CIDR deny policies may not take effect when a more narrow CIDR allow is present

    HighCVSS 8.7No exploitEPSS 0%

    cilium · ciliumOct 21, 2024

  • Bypass of namespace restrictions in CiliumNetworkPolicy

    HighCVSS 8.1No exploitEPSS 0%

    cilium · ciliumSep 27, 2023

  • Improper Privilege Management in Cilium

    HighCVSS 8.2No exploitEPSS 0%

    cilium · ciliumMay 20, 2022

  • Incorrect Default Permissions in Cilium

    HighCVSS 8.2No exploitEPSS 0%

    cilium · ciliumMay 20, 2022

  • Cilium vulnerable to potential network policy bypass when routing IPv6 traffic

    HighCVSS 7.3No exploitEPSS 1%

    cilium · ciliumMar 17, 2023

  • Cilium intermittent HTTP policy bypass

    HighCVSS 7.2No exploitEPSS 1%

    cilium · ciliumMar 18, 2024

  • Cilium vulnerable to information leakage via incorrect ReferenceGrant update logic in Gateway API

    HighCVSS 7.2No exploitEPSS 1%

    cilium · ciliumAug 16, 2024

  • Cilium agent's race condition may lead to policy bypass for Host Firewall policy

    MediumCVSS 6.8No exploitEPSS 1%

    cilium · ciliumAug 15, 2024

  • Insecure IPsec transport encryption in Cilium

    MediumCVSS 6.8No exploitEPSS 0%

    cilium · ciliumMar 27, 2024

  • Cilium vulnerable to information leakage via insecure default Hubble UI CORS header

    MediumCVSS 6.5No exploitEPSS 0%

    cilium · ciliumJan 22, 2025

  • Cilium leaks sensitive information in cilium-bugtool

    MediumCVSS 6.5No exploitEPSS 0%

    cilium · ciliumJun 13, 2024

  • Debug mode leaks confidential data in Cilium

    MediumCVSS 6.3No exploitEPSS 0%

    cilium · ciliumApr 18, 2023

  • Cilium has possible unencrypted traffic between nodes when using IPsec and L7 policies

    MediumCVSS 6.1No exploitEPSS 0%

    cilium · ciliumMar 18, 2024

  • Cilium has possible unencrypted traffic between nodes when using WireGuard and L7 policies

    MediumCVSS 6.1No exploitEPSS 0%

    cilium · ciliumMar 18, 2024

  • Layer 7 policy enforcement may not occur in policies with wildcarded port ranges in Cilium

    MediumCVSS 5.8No exploitEPSS 1%

    cilium · ciliumNov 25, 2024

  • cilium-agent container can access the host via `hostPath` mount

    MediumCVSS 5.5No exploitEPSS 0%

    cilium · ciliumMar 17, 2023

  • Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

    MediumCVSS 5.5No exploitEPSS 0%

    cilium · ciliumNov 28, 2025

  • Potential HTTP policy bypass when using header rules in Cilium

    MediumCVSS 5.3No exploitEPSS 1%

    cilium · ciliumMay 25, 2023

  • DoS in Cilium agent DNS proxy from crafted DNS responses

    MediumCVSS 5.3No exploitEPSS 0%

    cilium · ciliumJan 22, 2025

  • Cilium vulnerable to information leakage via incorrect ReferenceGrant handling

    MediumCVSS 5.3No exploitEPSS 0%

    cilium · ciliumJun 15, 2023

  • Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

    MediumCVSS 5.4No exploitEPSS 0%

    cilium · ciliumJul 15, 2026