CVE Explorer
CVE-2025-67499
The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the nftables backend, thus ignoring the destination IP. This includes traffic not intended for the node itself, i.e. traffic to containers hosted on the node. Containers that request HostPort forwarding can intercept all traffic d
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"plugins","vendor":"containernetworking","versions":[{"status":"affected","version":">= 1.6.0, < 1.9.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/containernetworking/plugins/pull/1210","tags":["x_refsource_MISC"],"url":"https://github.com/containernetworking/plugins/pull/1210"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/references/1
{"name":"https://github.com/containernetworking/plugins/releases/tag/v1.9.0","tags":["x_refsource_MISC"],"url":"https://github.com/containernetworking/plugins/releases/tag/v1.9.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/references/2
{"name":"https://github.com/containernetworking/plugins/security/advisories/GHSA-jv3w-x3r3-g6rm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/containernetworking/plugins/security/advisories/GHSA-jv3w-x3r3-g6rm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4461fe83bd443bb5a646d26b15009aa2f654e32f35d2c0c076bacb740f11e2aa · sha256:b4fdb131d345c136… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.