Affected by GO-2025-3560
and 2 other vulnerabilities
GO-2025-3560: Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers in github.com/cilium/cilium
GO-2025-3635: In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters in github.com/cilium/cilium
GO-2025-4167: Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic in Ciliumgithub.com/cilium/cilium
type Restorer interface {
// WaitForEndpointRestore blocks the caller until either the context is// cancelled or all the endpoints have been restored from a previous run.
WaitForEndpointRestore(ctx context.Context)
}
Restorer wraps a method to wait for endpoints restoration.