CVE-2025-67499 describes a vulnerability in the CNI portmap plugin, specifically versions 1.6.0 through 1.8.0, when configured with the nftables backend. This flaw allows containers requesting HostPort forwarding to inadvertently intercept all traffic destined for that port, regardless of the intended destination IP, including traffic meant for other containers on the node. With a CVSS score of 6.6 (Medium), this vulnerability has a local attack vector and low attack complexity, potentially leading to limited confidentiality and integrity impact, but high availability impact. There is currently no known active exploitation, publicly available exploit code, or significant community discussion beyond a single mention and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0, < 1.9.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:cni_network_plugins:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CNI portmap plugin: github.com/containernetworking/plugins/plugins/meta/portmap: CNI portmap plugin: HostPort forwarding vulnerability allows traffic interception
Dec 9, 2025CNA Plugins Portmap nftables backend can intercept non-local traffic
Dec 9, 2025