CVE-2025-59824 describes a medium-severity vulnerability in Omni versions prior to 0.48.0, where the Omni Wireguard SideroLink could be escaped. This allows a malicious workload on a Kubernetes cluster, particularly those with host networking, to send arbitrary packets over the SideroLink interface due to insufficient destination address validation. The CVSS score of 5.4 indicates a network-based attack with low privileges required, leading to potential low impact on confidentiality and integrity. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability has been patched in Omni version 0.48.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.48.0CPE matchmatch criteria | cpe:2.3:a:siderolabs:omni:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.