CVE-2025-30162

CVSS 3.1 Score 3.2 of 10 (low)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 863

Summary

CVE-2025-30162 is a vulnerability affecting Cilium, a networking, observability, and security solution. This issue occurs when using the Gateway API for Ingress, LB-IPAM or BGP for Load Balancer Service implementation, and network policies to block egress traffic between certain namespaces. Contrary to expectations, egress traffic to LoadBalancers configured via Gateway resources is inadvertently permitted. Notably, LoadBalancer resources not deployed via Gateway API are not affected. This issue impacts Cilium versions 1.15 through 1.15.14, 1.16 through 1.16.7, and 1.17 through 1.17.1. Affected users unable to upgrade can implement a Clusterwide Cilium Network Policy as a temporary workaround.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share