DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-32793

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-32793

Severity

4.0

Medium

CVSS V3

Summary

Cilium packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

Description

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a terminating endpoint can leave the source node without encryption due to a race condition in how traffic is processed by Cilium. This issue has been patched in versions 1.15.16, 1.16.9, and 1.17.3. There are no workarounds available for this issue.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-32793

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing