The Cilium CNI providing pod networking, network policy and load balancing via eBPF.
Version: 1.20.2
Type: Container
License:
| Expand | CVE | Title | Status | |
|---|---|---|---|---|
| GHSA-2v4p-qf9q-27wj Open GHSA-2v4p-qf9q-27wj in a new tab | gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers | Not affected | High | |
| GHSA-frrj-87jh-2772 Open GHSA-frrj-87jh-2772 in a new tab | GoBGP confederation validation panics on empty AS_PATH attribute | Not affected | Medium | |
| GHSA-gcjh-h69q-9w9g Open GHSA-gcjh-h69q-9w9g in a new tab | cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag | Not affected | Medium | |
| GO-2026-4736 Open GO-2026-4736 in a new tab | GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp | Not affected | Unknown | |
| GO-2026-5024 Open GO-2026-5024 in a new tab | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | Not affected | Unknown | |
| GO-2026-5024 Open GO-2026-5024 in a new tab | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | Not affected | Unknown | |
| GO-2026-5841 Open GO-2026-5841 in a new tab | OOB read in github.com/klauspost/compress/s2 | Not affected | Unknown | |
| GO-2026-5932 Open GO-2026-5932 in a new tab | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | Not affected | Unknown | |
| GO-2026-5954 Open GO-2026-5954 in a new tab | GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp | Not affected | Unknown | |
| GO-2026-6094 Open GO-2026-6094 in a new tab | JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go | Not affected | Unknown | |
| GO-2026-6107 Open GO-2026-6107 in a new tab | Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 | Not affected | Unknown | |
| GO-2026-6303 Open GO-2026-6303 in a new tab | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6354 Open GO-2026-6354 in a new tab | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6355 Open GO-2026-6355 in a new tab | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6443 Open GO-2026-6443 in a new tab | Server panic via missing authority or Host headers in google.golang.org/grpc | Not affected | Unknown |
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
GoBGP confederation validation panics on empty AS_PATH attribute
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp
Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
OOB read in github.com/klauspost/compress/s2
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Server panic via missing authority or Host headers in google.golang.org/grpc