<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:34:49 +0000</lastBuildDate>
    <item>
      <title>BIT-cilium-2025-30162 — East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers</title>
      <link>https://cve.radiocsirt.org/vuln/bit-cilium-2025-30162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cilium&lt;/p&gt;
&lt;p&gt;Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed. LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue. This issue affects: Cilium v1.15 between v1.15.0 and v1.15.14 inclusive, v1.16 between v1.16.0 and v1.16.7 inclusive, and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.15.15, v1.16.8, and v1.17.2. A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: cilium&lt;/p&gt;
&lt;p&gt;Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed. LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue. This issue affects: Cilium v1.15 between v1.15.0 and v1.15.14 inclusive, v1.16 between v1.16.0 and v1.16.7 inclusive, and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.15.15, v1.16.8, and v1.17.2. A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-cilium-2025-30162</guid>
    </item>
    <item>
      <title>EUVD-2026-224689</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-224689</link>
      <description>EUVD-2026-224689</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-224689</guid>
    </item>
    <item>
      <title>fkie_cve-2025-30162</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-30162</link>
      <description>&lt;p&gt;Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed. LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue. This issue affects: Cilium v1.15 between v1.15.0 and v1.15.14 inclusive, v1.16 between v1.16.0 and v1.16.7 inclusive, and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.15.15, v1.16.8, and v1.17.2. A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces, egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed. LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue. This issue affects: Cilium v1.15 between v1.15.0 and v1.15.14 inclusive, v1.16 between v1.16.0 and v1.16.7 inclusive, and v1.17 between v1.17.0 and v1.17.1 inclusive. This issue is fixed in Cilium v1.15.15, v1.16.8, and v1.17.2. A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-30162</guid>
    </item>
    <item>
      <title>GHSA-24qp-4xx8-3jvj — Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-24qp-4xx8-3jvj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cilium/cilium&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;For Cilium users who:
- Use Gateway API for Ingress for some services **AND**
- Use [LB-IPAM](https://docs.cilium.io/en/stable/network/lb-ipam/) or BGP for LB Service implementation **AND**
- Use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces&lt;/p&gt;
&lt;p&gt;Egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed.&lt;/p&gt;
&lt;p&gt;LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue was fixed by https://github.com/cilium/proxy/pull/1172.&lt;/p&gt;
&lt;p&gt;This issue affects:&lt;/p&gt;
&lt;p&gt;- Cilium v1.15 between v1.15.0 and v1.15.14 inclusive
- Cilium v1.16 between v1.16.0 and v1.16.7 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.1 inclusive&lt;/p&gt;
&lt;p&gt;This issue is fixed in:&lt;/p&gt;
&lt;p&gt;- Cilium v1.15.15
- Cilium v1.16.8
- Cilium v1.17.2&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade. An outline of such a policy is provided below:&lt;/p&gt;
&lt;p&gt;```
apiVersion: &amp;#34;cilium.io/v2&amp;#34;
kind: CiliumClusterwideNetworkPolicy
metadata:
  name: &amp;#34;workaround&amp;#34;
spec:
  endpointSelector:
    matchExpressions:
    - key: reserved:ingress
      operator: Exists
  ingress:
  - fromEntities:
    - world
```&lt;/p&gt;
&lt;p&gt;- The policy opens up connectivity from all locations outside the cluster into the Cilium Ingress Gateway.
- The policy establishes a default deny for all other traffic towards the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cilium/cilium&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;For Cilium users who:
- Use Gateway API for Ingress for some services **AND**
- Use [LB-IPAM](https://docs.cilium.io/en/stable/network/lb-ipam/) or BGP for LB Service implementation **AND**
- Use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces&lt;/p&gt;
&lt;p&gt;Egress traffic from workloads covered by such network policies to LoadBalancers configured by `Gateway` resources will incorrectly be allowed.&lt;/p&gt;
&lt;p&gt;LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue was fixed by https://github.com/cilium/proxy/pull/1172.&lt;/p&gt;
&lt;p&gt;This issue affects:&lt;/p&gt;
&lt;p&gt;- Cilium v1.15 between v1.15.0 and v1.15.14 inclusive
- Cilium v1.16 between v1.16.0 and v1.16.7 inclusive
- Cilium v1.17 between v1.17.0 and v1.17.1 inclusive&lt;/p&gt;
&lt;p&gt;This issue is fixed in:&lt;/p&gt;
&lt;p&gt;- Cilium v1.15.15
- Cilium v1.16.8
- Cilium v1.17.2&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;A Clusterwide Cilium Network Policy can be used to work around this issue for users who are unable to upgrade. An outline of such a policy is provided below:&lt;/p&gt;
&lt;p&gt;```
apiVersion: &amp;#34;cilium.io/v2&amp;#34;
kind: CiliumClusterwideNetworkPolicy
metadata:
  name: &amp;#34;workaround&amp;#34;
spec:
  endpointSelector:
    matchExpressions:
    - key: reserved:ingress
      operator: Exists
  ingress:
  - fromEntities:
    - world
```&lt;/p&gt;
&lt;p&gt;- The policy opens up connectivity from all locations outside the cluster into the Cilium Ingress Gateway.
- The policy establishes a default deny for all other traffic towards the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-24qp-4xx8-3jvj</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14937-1 — govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250327T184518-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14937-1</guid>
    </item>
  </channel>
</rss>
