Cilium Sensitive Data Exposure Vulnerability in cilium-bugtool Prior to 1.17.15, 1.18.9 and 1.19.3

Vulnerability

A vulnerability exists in Cilium's cilium-bugtool debug utility, which can inadvertently include sensitive information when run on Cilium deployments with WireGuard encryption enabled. This issue is present in Cilium versions prior to 1.17.15, as well as versions 1.18.0 through 1.18.8 and 1.19.0 through 1.19.2. The sensitive data exposed includes the WireGuard private key used for encrypted communication between nodes.

Impact

The vulnerability allows the WireGuard private key to be included in the cilium-bugtool output, posing a risk of unauthorized access to encrypted communications between nodes.

Remediation

Users should update to Cilium versions 1.17.15, 1.18.9, or 1.19.3. For those who have shared bugtool or sysdump archives from WireGuard-enabled nodes, it is recommended to rotate the WireGuard keys on the affected nodes by deleting the key file, restarting the Cilium agent, and allowing it to generate a new key pair.

Added: May 8, 2026, 11:30 PM
Updated: May 8, 2026, 11:30 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
3.5
remediation
8.3
relevance
7.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.