CVE-2025-30163
CVSS 3.1 Score 3.4 of 10 (low)
Details
Summary
CVE-2025-30163 is a vulnerability affecting Cilium, a networking, observability, and security solution with an eBPF-based dataplane. This issue allows traffic to bypass node-based network policies due to incorrect permittraffic to endpoints sharing labels in `fromNodes` and `toNodes` sections. Affected versions include Cilium v1.16 between v1.16.0 and v1.16.7, and v1.17 between v1.17.0 and v1.17.1. Node-based network policy is disabled by default in Cilium. To mitigate the issue, users must ensure that labels used in `fromNodes` and `toNodes` fields are exclusively applied to nodes, not endpoints. This vulnerability has been fixed in Cilium v1.16.8 and v1.17.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cilium
Affected Vendors
- Cilium