Affected by GO-2024-2653
and 17 other vulnerabilities
GO-2024-2653: HTTP policy bypass in github.com/cilium/cilium
GO-2024-2656: Unencrypted traffic between nodes with IPsec in github.com/cilium/cilium
GO-2024-2657: Unencrypted traffic between nodes with WireGuard in github.com/cilium/cilium
GO-2024-2666: Insecure IPsec transparent encryption in github.com/cilium/cilium
GO-2024-2922: Cilium leaks sensitive information in cilium-bugtool in github.com/cilium/cilium
GO-2024-3071: Gateway API route matching order contradicts specification in github.com/cilium/cilium
GO-2024-3072: Policy bypass for Host Firewall policy due to race condition in Cilium agent in github.com/cilium/cilium
GO-2024-3074: Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API in github.com/cilium/cilium
GO-2024-3208: Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present in github.com/cilium/cilium
GO-2025-3415: DoS in Cilium agent DNS proxy from crafted DNS responses in github.com/cilium/cilium
GO-2025-3416: Cilium has an information leakage via insecure default Hubble UI CORS header in github.com/cilium/cilium
GO-2025-3560: Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers in github.com/cilium/cilium
GO-2025-3635: In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
GO-2025-4167: Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
GO-2026-4856: Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic in github.com/cilium/cilium
GO-2026-5400: Cillium exposes sensitive information included in the cilium-bugtool debug archive in github.com/cilium/cilium
GO-2026-5905: Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access in github.com/cilium/cilium
GO-2026-5914: CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation in github.com/cilium/cilium
type MonitorConsumer interface {
// NotifyAgentEvent informs the consumer about a new monitor event// sent from cilium-agent. The concrete type of the message parameter// depends on the value of typ:// - MessageTypeAccessLog: accesslog.LogRecord// - MessageTypeAgent: api.AgentNotify
NotifyAgentEvent(typ int, message interface{})
// NotifyPerfEvent informs the consumer about an datapath event obtained// via perf events ring buffer.// Data contains the raw binary encoded perf payload. The underlying type// depends on the value of typ:// - MessageTypeDrop: monitor.DropNotify// - MessageTypeDebug: monitor.DebugMsg// - MessageTypeCapture: monitor.DebugCapture// - MessageTypeTrace: monitor.TraceNotify// - MessageTypePolicyVerdict: monitor.PolicyVerdictNotify
NotifyPerfEvent(data []byte, cpu int)
// NotifyPerfEventLost informs the consumer that a number of events have// been lost due to the perf event ring buffer not being read.
NotifyPerfEventLost(numLostEvents uint64, cpu int)
}
MonitorConsumer is a consumer of decoded monitor events