CVE Explorer
CVE-2026-34992
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea fails to apply encryption for IPv6 Pod traffic. While the IPv4 traffic is correctly encrypted via ESP (Encapsulating Security Payload), traffic using IPv6 is transmitted in plaintext. This occurs because t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"antrea","vendor":"antrea-io","versions":[{"status":"affected","version":"< 2.4.5"},{"status":"affected","version":">= 2.5.0, < 2.5.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-311","description":"CWE-311: Missing Encryption of Sensitive Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/antrea-io/antrea/blob/main/docs/traffic-encryption.md","tags":["x_refsource_MISC"],"url":"https://github.com/antrea-io/antrea/blob/main/docs/traffic-encryption.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/references/4
{"name":"https://github.com/antrea-io/antrea/commit/738bad662b20a5d358d19466936176ef580a9b07","tags":["x_refsource_MISC"],"url":"https://github.com/antrea-io/antrea/commit/738bad662b20a5d358d19466936176ef580a9b07"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/references/3
{"name":"https://github.com/antrea-io/antrea/pull/7757","tags":["x_refsource_MISC"],"url":"https://github.com/antrea-io/antrea/pull/7757"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/references/1
{"name":"https://github.com/antrea-io/antrea/pull/7759","tags":["x_refsource_MISC"],"url":"https://github.com/antrea-io/antrea/pull/7759"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/references/2
{"name":"https://github.com/antrea-io/antrea/security/advisories/GHSA-qcmw-8mm4-4p28","tags":["x_refsource_CONFIRM"],"url":"https://github.com/antrea-io/antrea/security/advisories/GHSA-qcmw-8mm4-4p28"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f812cf9859cbc468bf9cac374e4d89dace16ae3ae96a1f016d8b8d0fd3ba2b10 · sha256:c12dfa948257f3c1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.