Cilium node based network policies may incorrectly allow workload traffic (CVE-2025-30163)
### Impact [Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. ### Patches This issue was fixed by https://github.com/cilium/cilium/pull/36657. This issue affects: - Cilium v1.16 between v1.16.0 and v1.16.7 inclusive - Cilium v1.17 between v1.17.0 and v1.17.1 inclusive This issue is fixed in: - Cilium v1.16.8 - Cilium v1.17.2 ### Workarounds Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @oblazek for reporting and fixing this issue. ### For more information If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and your report will be treated as top priority. Please also address any comments or questions on this advisory to the same mailing list.
AI Analysis
Technical Summary
Cilium node based network policies that use fromNodes and toNodes selectors may permit traffic from or to non-node endpoints if those endpoints share the same labels specified in the policy. This behavior is unintended and could lead to incorrect network access permissions. The vulnerability affects Cilium versions 1.16.0 up to and including 1.16.7 and 1.17.0 up to and including 1.17.1. The issue was resolved in versions 1.16.8 and 1.17.2. Node based network policy is disabled by default, reducing exposure. A workaround is to restrict labels in fromNodes and toNodes to nodes only.
Potential Impact
The vulnerability allows workload traffic from or to non-node endpoints that share node labels to bypass intended network policy restrictions. This could lead to unintended network communication paths. The impact is limited to confidentiality as per the CVSS vector (C:L/I:N/A:N). Node based network policy is disabled by default, which reduces the attack surface. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available in Cilium versions 1.16.8 and 1.17.2. Users should upgrade to these versions or later to remediate the issue. Alternatively, users can work around the issue by ensuring that labels used in fromNodes and toNodes are assigned exclusively to nodes and not to other endpoints. Since node based network policy is disabled by default, enabling it should be done with caution until patched.
Cilium node based network policies may incorrectly allow workload traffic (CVE-2025-30163)
Description
### Impact [Node based network policies](https://docs.cilium.io/en/stable/security/policy/language/#node-based) (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` and `toNodes` sections of network policies. Node based network policy is disabled by default in Cilium. ### Patches This issue was fixed by https://github.com/cilium/cilium/pull/36657. This issue affects: - Cilium v1.16 between v1.16.0 and v1.16.7 inclusive - Cilium v1.17 between v1.17.0 and v1.17.1 inclusive This issue is fixed in: - Cilium v1.16.8 - Cilium v1.17.2 ### Workarounds Users can work around this issue by ensuring that the labels used in `fromNodes` and `toNodes` fields are used exclusively by nodes and not by other endpoints. ### Acknowledgements The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @oblazek for reporting and fixing this issue. ### For more information If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [[email protected]](mailto:[email protected]). This is a private mailing list for the Cilium security team, and your report will be treated as top priority. Please also address any comments or questions on this advisory to the same mailing list.
CVSS v3.1
Score 3.4low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cilium node based network policies that use fromNodes and toNodes selectors may permit traffic from or to non-node endpoints if those endpoints share the same labels specified in the policy. This behavior is unintended and could lead to incorrect network access permissions. The vulnerability affects Cilium versions 1.16.0 up to and including 1.16.7 and 1.17.0 up to and including 1.17.1. The issue was resolved in versions 1.16.8 and 1.17.2. Node based network policy is disabled by default, reducing exposure. A workaround is to restrict labels in fromNodes and toNodes to nodes only.
Potential Impact
The vulnerability allows workload traffic from or to non-node endpoints that share node labels to bypass intended network policy restrictions. This could lead to unintended network communication paths. The impact is limited to confidentiality as per the CVSS vector (C:L/I:N/A:N). Node based network policy is disabled by default, which reduces the attack surface. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available in Cilium versions 1.16.8 and 1.17.2. Users should upgrade to these versions or later to remediate the issue. Alternatively, users can work around the issue by ensuring that labels used in fromNodes and toNodes are assigned exclusively to nodes and not to other endpoints. Since node based network policy is disabled by default, enabling it should be done with caution until patched.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c6pf-2v8j-96mc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-30163"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a46ecb327e9c7971943c625
Added to database: 07/02/2026, 22:56:51 UTC
Last enriched: 07/02/2026, 23:08:51 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.