CVE-2025-30162: Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
For Cilium users who:
- Use Gateway API for Ingress for some services AND
- Use LB-IPAM or BGP for LB Service implementation AND
- Use network policies to block egress traffic from workloads in a namespace to workloads in other namespaces
Egress traffic from workloads covered by such network policies to LoadBalancers configured by Gateway
resources will incorrectly be allowed.
LoadBalancer resources not deployed via a Gateway API configuration are not affected by this issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-30162 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →