CVE-2025-32793: Cilium

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. This issue has been patched in versions 1.15.16, 1.16.9, and 1.17.3. There are no workarounds available for this issue.

Affected products

  • Cilium Cilium: from 1.13.0, before 1.15.16 (fixed in 1.15.16); from 1.16.0, before 1.16.9 (fixed in 1.16.9); from 1.17.0, before 1.17.3 (fixed in 1.17.3)

Published 2025-04-21. Last modified 2026-06-17.