CVE-2025-30162
CVSS 3.1 Score 3.2 of 10 (low)
Details
Summary
CVE-2025-30162 is a vulnerability affecting Cilium, a networking, observability, and security solution. This issue occurs when using the Gateway API for Ingress, LB-IPAM or BGP for Load Balancer Service implementation, and network policies to block egress traffic between certain namespaces. Contrary to expectations, egress traffic to LoadBalancers configured via Gateway resources is inadvertently permitted. Notably, LoadBalancer resources not deployed via Gateway API are not affected. This issue impacts Cilium versions 1.15 through 1.15.14, 1.16 through 1.16.7, and 1.17 through 1.17.1. Affected users unable to upgrade can implement a Clusterwide Cilium Network Policy as a temporary workaround.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cilium
Affected Vendors
- Cilium