Database/Container, Kubernetes & orchestration
Cilium: On agent start, eBPF programs are briefly detached, so traffic bypasses NetworkPolicy
CVSS 6.5CVE-2023-27595Container, Kubernetes & orchestrationcurated
Impact
On agent start, eBPF programs are briefly detached, so traffic bypasses NetworkPolicy
Who can reach it
Any pod on the cluster network during an agent restart
What to do
Upgrade Cilium; note that every agent restart, including your own upgrades, is a policy-gap window
References
Related entries
- Cilium: Insecure default Access-Control-Allow-Origin in Hubble UI exposes sensitive observability dataCVE-2025-23047 · CiliumMedium
- Cilium: WireGuard transparent encryption not applied to some pod trafficCVE-2024-25630 · CiliumMedium
- Cilium: With an external kvstore and WireGuard, pod-to-pod traffic is unencryptedCVE-2024-25631 · CiliumMedium
- Cilium: IPsec-eligible traffic matching L7 policy is sent unencryptedCVE-2024-28249 · CiliumMedium
- Cilium: WireGuard-eligible traffic matching L7 policy is sent unencrypted between nodesCVE-2024-28250 · CiliumMedium
- Cilium: With native routing plus WireGuard node encryption, traffic from pods on other nodes is wrongly permittedCVE-2026-26963 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.