pkg:Bitnami/cilium-operator

32 total CVEsHIGH7MEDIUM21LOW4

✅ Check your installed version

All known vulnerabilities

  • HIGH8.8CVE-2022-29178Access to Unix domain socket can lead to privileges escalation in Cilium
    from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
  • HIGH8.0CVE-2024-28860Insecure IPsec transparent encryption in github.com/cilium/cilium
    >= 1.14.0, < 1.14.9, >= 1.15.0, < 1.15.3 | >= 1.4.0, <= 1.13.14
  • HIGH7.9CVE-2026-41520Cillium exposes sensitive information included in the cilium-bugtool debug archive
    from 0, < 1.17.15, >= 1.18.0, < 1.18.9, >= 1.19.0, < 1.19.3
  • HIGH7.9CVE-2024-37307Cilium leaks sensitive information in cilium-bugtool
    >= 1.15.4, < 1.15.6
  • HIGH7.5CVE-2022-29179Improper Privilege Management in Cilium in github.com/cilium/cilium
    from 0, < 1.9.16, >= 1.10.0, < 1.10.11, >= 1.11.0, < 1.11.5
  • HIGH7.2CVE-2024-28248Intermittent HTTP policy bypass
    >= 1.13.9, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
  • HIGH7.2CVE-2023-29002Debug mode leaks confidential data in Cilium
    >= 1.7.0, < 1.11.16, >= 1.12.0, < 1.12.9, >= 1.13.0, < 1.13.2
  • MEDIUM6.9CVE-2023-41333Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
    from 0, < 1.12.14, >= 1.13.0, < 1.13.7, >= 1.14.0, < 1.14.2
  • MEDIUM6.8CVE-2024-42488Policy bypass for Host Firewall policy due to race condition in Cilium agent
    >= 1.15.4, < 1.16.0
  • MEDIUM6.5CVE-2025-23047Cilium has an information leakage via insecure default Hubble UI CORS header
    >= 1.15.4, < 1.16.5
  • MEDIUM6.5CVE-2023-27595Cilium eBPF filters may be temporarily removed during agent restart in github.com/cilium/cilium
    >= 1.13.0, < 1.13.1
  • MEDIUM6.1CVE-2026-26963Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabled
    >= 1.18.0, < 1.18.6
  • MEDIUM6.1CVE-2024-28250Unencrypted traffic between nodes with WireGuard in github.com/cilium/cilium
    >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
  • MEDIUM6.1CVE-2024-28249Unencrypted traffic between nodes when using IPsec and L7 policies
    from 0, < 1.13.13, >= 1.14.0, < 1.14.8, >= 1.15.0, < 1.15.2
  • MEDIUM6.1CVE-2024-25631Unencrypted traffic between pods when using Wireguard and an external kvstore
    from 0, < 1.14.7
  • MEDIUM6.1CVE-2024-25630Unencrypted ingress/health traffic when using Wireguard transparent encryption in github.com/cilium/cilium
    >= 1.14.0, < 1.14.7
  • MEDIUM5.8CVE-2024-52529Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port ranges in github.com/cilium/cilium
    >= 1.16.0, < 1.16.4
  • MEDIUM5.4CVE-2026-33726Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
    from 0, < 1.17.14, >= 1.18.0, < 1.18.8, >= 1.19.0, < 1.19.2
  • MEDIUM5.4CVE-2024-42486Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API in github.com/cilium/cilium
    >= 1.15.4, < 1.16.1
  • MEDIUM5.4CVE-2023-39347Kubernetes users may update Pod labels to bypass network policy in github.com/cilium/cilium
    from 0, < 1.12.14, >= 1.13.0, < 1.13.7, >= 1.14.0, < 1.14.2
  • MEDIUM5.3CVE-2025-23028DoS in Cilium agent DNS proxy from crafted DNS responses
    >= 1.15.4, < 1.16.5
  • MEDIUM5.3CVE-2023-30851Potential HTTP policy bypass when using header rules in Cilium
    from 0, < 1.11.16, >= 1.12.0, < 1.12.9, >= 1.13.0, < 1.13.2
  • MEDIUM4.4CVE-2023-27593cilium-agent container can access the host via `hostPath` mount
    from 0, < 1.11.15, >= 1.12.0, < 1.12.8, >= 1.13.0, < 1.13.1
  • MEDIUM4.2CVE-2023-27594Potential network policy bypass when routing IPv6 traffic in github.com/cilium/cilium
    from 0, < 1.11.15, >= 1.12.0, < 1.12.8, >= 1.13.0, < 1.13.1
  • MEDIUM4.0CVE-2025-64715Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
    from 0, < 1.16.17, >= 1.17.0, < 1.17.10, >= 1.18.0, < 1.18.4
  • MEDIUM4.0CVE-2025-32793In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
    >= 1.13.0, < 1.17.3
  • MEDIUM4.0CVE-2024-47825Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
    >= 1.15.4, < 1.16.0
  • MEDIUM4.0CVE-2024-42487Gateway API route matching order contradicts specification
    >= 1.15.4, < 1.16.1
  • LOW3.5CVE-2023-41332Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
    from 0, < 1.12.14, >= 1.13.0, < 1.13.7, >= 1.14.0, < 1.14.2
  • LOW3.4CVE-2025-30163Cilium node based network policies may incorrectly allow workload traffic in github.com/cilium/cilium
    >= 1.16.0, < 1.17.2
  • LOW3.4CVE-2023-34242Cilium vulnerable to information leakage via incorrect ReferenceGrant handling in github.com/cilium/cilium
    from 0, < 1.13.4
  • LOW3.2CVE-2025-30162Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers in github.com/cilium/cilium
    >= 1.15.0, < 1.17.2