HarborGuard / CVE
Back to search
HIGHCVE-2026-41520Published Modified CNA GitHub_M

CVE-2026-41520: Cillium exposes sensitive information included in the cilium-bugtool debug archive

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. This issue has been patched in versions 1.17.15, 1.18.9, and 1.19.3.

Metrics

CVSS v3.1
7.9
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • cilium / cilium
    < 1.17.15 · >= 1.18.0, < 1.18.9 · >= 1.19.0, < 1.19.3
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N