-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/cilium/cilium | go | < 1.11.16 | 1.11.16 |
| github.com/cilium/cilium | go | >= 1.12.0, < 1.12.9 | 1.12.9 |
| github.com/cilium/cilium | go | >= 1.13.0, < 1.13.2 | 1.13.2 |
The vulnerability stems from improper merging of HTTP rules when multiple toEndpoints are specified. The workaround requires separating rules per endpoint, indicating the core issue was in rule aggregation logic. The patched versions fix 'incorrect merging of L7 rules' (per release notes), and the CWE-693 (Protection Mechanism Failure) aligns with flawed policy enforcement. The most logical location for this logic is in HTTP rule merging functions within the policy API layer.
Ongoing coverage of React2Shell