Executive brief
Cilium is a networking and security tool used to manage and secure communication between applications in cloud environments. A vulnerability in its diagnostic tool, cilium-bugtool, could allow sensitive information to be exposed in plain text when WireGuard encryption is enabled. If an attacker with high-level system access obtains these diagnostic logs, they could potentially access sensitive configuration data or encryption details, compromising the security of the network.
Technical details
A sensitive information disclosure vulnerability exists in Cilium's diagnostic utility, cilium-bugtool. When the tool is executed on a Cilium deployment where WireGuard encryption is enabled, the resulting output may contain sensitive data in cleartext. This issue is classified under CWE-200 (Exposure of Sensitive Information) and CWE-312 (Cleartext Storage of Sensitive Information). An attacker with local access and high privileges (PR:H) could exploit this to retrieve sensitive cryptographic or configuration details from the bugtool's output. The vulnerability has been addressed in versions 1.17.15, 1.18.9, and 1.19.3 by ensuring sensitive data is properly redacted or excluded from diagnostic reports.
Affected products
- Cilium Cilium < 1.17.15, < 1.18.9, < 1.19.3
Timeline
- 2026-04-15: patched: Fixes included in releases 1.17.15, 1.18.9, and 1.19.3
- 2026-05-08: disclosed: CVE published