CVE-2026-41520 Details
Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled. This issue has been patched in versions 1.17.15, 1.18.9, and 1.19.3.
A vulnerability exists in Cilium's cilium-bugtool debug utility, which can inadvertently include sensitive information when run on Cilium deployments with WireGuard encryption enabled. This issue is present in Cilium versions prior to 1.17.15, as well as versions 1.18.0 through 1.18.8 and 1.19.0 through 1.19.2. The sensitive data exposed includes the WireGuard private key used for encrypted communication between nodes.
Users should update to Cilium versions 1.17.15, 1.18.9, or 1.19.3. For those who have shared bugtool or sysdump archives from WireGuard-enabled nodes, it is recommended to rotate the WireGuard keys on the affected nodes by deleting the key file, restarting the Cilium agent, and allowing it to generate a new key pair.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cilium/cilium/releases/tag/v1.17.15 | [email protected] | ProductRelease Notes |
| https://github.com/cilium/cilium/releases/tag/v1.18.9 | [email protected] | ProductRelease Notes |
| https://github.com/cilium/cilium/releases/tag/v1.19.3 | [email protected] | ProductRelease Notes |
| https://github.com/cilium/cilium/security/advisories/GHSA-gj49-89wh-h4gj | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cilium cilium | < 1.17.15 >= 1.18.0, < 1.18.9 >= 1.19.0, < 1.19.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |