CVE-2025-30163

CVSS 3.1 Score 3.4 of 10 (low)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 863

Summary

CVE-2025-30163 is a vulnerability affecting Cilium, a networking, observability, and security solution with an eBPF-based dataplane. This issue allows traffic to bypass node-based network policies due to incorrect permittraffic to endpoints sharing labels in `fromNodes` and `toNodes` sections. Affected versions include Cilium v1.16 between v1.16.0 and v1.16.7, and v1.17 between v1.17.0 and v1.17.1. Node-based network policy is disabled by default in Cilium. To mitigate the issue, users must ensure that labels used in `fromNodes` and `toNodes` fields are exclusively applied to nodes, not endpoints. This vulnerability has been fixed in Cilium v1.16.8 and v1.17.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share