Skip to main content
EPSS 0.2%top 89%

Cilium node based network policies may incorrectly allow workload traffic (CVE-2025-30163)

0
Low
Published: 03/24/2025 (03/24/2025, 19:36:21 UTC)
Source: GCVE Database
Product: github.com/cilium/cilium

Description

### Impact [Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. ### Patches This issue was fixed by https://github.com/cilium/cilium/pull/36657. This issue affects: - Cilium v1.16 between v1.16.0 and v1.16.7 inclusive - Cilium v1.17 between v1.17.0 and v1.17.1 inclusive This issue is fixed in: - Cilium v1.16.8 - Cilium v1.17.2 ### Workarounds Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @oblazek for reporting and fixing this issue. ### For more information If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and your report will be treated as top priority. Please also address any comments or questions on this advisory to the same mailing list.

CVSS v3.1

Score 3.4low

Attack Vector
Adjacent Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected software

Goghsa
github.com/cilium/cilium
Affected versions
>=1.16.0 <1.16.8
Goghsa
github.com/cilium/cilium
Affected versions
>=1.17.0 <1.17.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/02/2026, 23:08:51 UTC

Technical Analysis

Cilium node based network policies that use fromNodes and toNodes selectors may permit traffic from or to non-node endpoints if those endpoints share the same labels specified in the policy. This behavior is unintended and could lead to incorrect network access permissions. The vulnerability affects Cilium versions 1.16.0 up to and including 1.16.7 and 1.17.0 up to and including 1.17.1. The issue was resolved in versions 1.16.8 and 1.17.2. Node based network policy is disabled by default, reducing exposure. A workaround is to restrict labels in fromNodes and toNodes to nodes only.

Potential Impact

The vulnerability allows workload traffic from or to non-node endpoints that share node labels to bypass intended network policy restrictions. This could lead to unintended network communication paths. The impact is limited to confidentiality as per the CVSS vector (C:L/I:N/A:N). Node based network policy is disabled by default, which reduces the attack surface. No known exploits are reported in the wild.

Mitigation Recommendations

A fix is available in Cilium versions 1.16.8 and 1.17.2. Users should upgrade to these versions or later to remediate the issue. Alternatively, users can work around the issue by ensuring that labels used in fromNodes and toNodes are assigned exclusively to nodes and not to other endpoints. Since node based network policy is disabled by default, enabling it should be done with caution until patched.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-c6pf-2v8j-96mc
Osv Schema Version
1.4.0
Aliases
["CVE-2025-30163"]
Ecosystems
["Go"]
Database Specific Severity
LOW
Cvss Version
3.1

Threat ID: 6a46ecb327e9c7971943c625

Added to database: 07/02/2026, 22:56:51 UTC

Last enriched: 07/02/2026, 23:08:51 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses