๐Ÿ” CVE Alert

CVE-2026-34992

UNKNOWN 0.0

Missing Encryption of Sensitive Data in antrea.io/antrea

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea fails to apply encryption for IPv6 Pod traffic. While the IPv4 traffic is correctly encrypted via ESP (Encapsulating Security Payload), traffic using IPv6 is transmitted in plaintext. This occurs because the packets are encapsulated (using Geneve or VXLAN) but bypass the IPsec encryption layer. Impacted Users: users with dual-stack clusters and IPsec encryption enabled. Single-stack IPv4 or IPv6 clusters are not affected. This vulnerability is fixed in 2.4.5 and 2.5.2.

CWE CWE-311
Vendor antrea-io
Product antrea
Published Apr 6, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for antrea-io antrea

Be the first to know when new unknown vulnerabilities affecting antrea-io antrea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

antrea-io / antrea
< 2.4.5 >= 2.5.0, < 2.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/antrea-io/antrea/security/advisories/GHSA-qcmw-8mm4-4p28 github.com: https://github.com/antrea-io/antrea/pull/7757 github.com: https://github.com/antrea-io/antrea/pull/7759 github.com: https://github.com/antrea-io/antrea/commit/738bad662b20a5d358d19466936176ef580a9b07 github.com: https://github.com/antrea-io/antrea/blob/main/docs/traffic-encryption.md