{"id":"GO-2024-3074","summary":"Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API in github.com/cilium/cilium","details":"Cilium leaks information via incorrect ReferenceGrant update logic in Gateway API in github.com/cilium/cilium","aliases":["BIT-cilium-2024-42486","BIT-cilium-operator-2024-42486","BIT-hubble-relay-2024-42486","CVE-2024-42486","GHSA-vwf8-q6fw-4wcm"],"modified":"2026-02-04T02:38:56.894312Z","published":"2024-08-19T17:26:32Z","related":["CGA-xg98-fvvw-83p7"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2024-3074","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/cilium/cilium/security/advisories/GHSA-vwf8-q6fw-4wcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42486"},{"type":"FIX","url":"https://github.com/cilium/cilium/commit/414a96b53d51ef6e6645c44426e26bc8e7c7c059"},{"type":"FIX","url":"https://github.com/cilium/cilium/commit/92c110e58a7be6586819dd51fb0f6ee1ec4be8f8"},{"type":"FIX","url":"https://github.com/cilium/cilium/commit/ed3dfa0aab8b80f7e841a6d49d2a990ac2dca053"},{"type":"FIX","url":"https://github.com/cilium/cilium/pull/34032"}],"affected":[{"package":{"name":"github.com/cilium/cilium","ecosystem":"Go","purl":"pkg:golang/github.com/cilium/cilium"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.15.0"},{"fixed":"1.15.8"},{"introduced":"1.16.0"},{"fixed":"1.16.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-3074.json"}}],"schema_version":"1.7.3"}