CVE-2025-67499: CNI Plugins Portmap nftables backend intercepts non-local traffic

Published Dec 9, 2025
·
Updated

Background

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. For example, if a host has the IP 198.51.100.42, a container may request that all packets to 198.51.100.42:53 be forwarded to the container's network.

Vulnerability

When the portmap plugin is configured with the nftables backend, it inadvertently forwards all traffic with the same destination port as the host port, ignoring the destination IP. This includes traffic not intended for the node itself, i.e. traffic to containers hosted on the node.

In the given example above, traffic destined to port 53 but for a separate container would still be captured and forwarded, even though it was not destined for the host.

Impact

Containers (i.e. kubernetes pods) that request HostPort forwarding can intercept all traffic destined for that port. This requires that the portmap plugin be explicitly configured to use the nftables backend. (The iptables backend is the default.)

Patches This is fixed as of CNI plugins v1.9.0

Workarounds Configure the portmap plugin to use the iptables backend. It does not have this vulnerability.

Other sources

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the nftables backend, thus ignoring the destination IP. This includes traffic not intended for the node itself, i.e. traffic to containers hosted on the node. Containers that request HostPort forwarding can intercept all traffic destined for that port. This requires that the portmap plugin be explicitly configured to use the nftables backend. This issue is fixed in version 1.9.0. To workaround, configure the portmap plugin to use the iptables backend. It does not have this vulnerability.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/containernetworking/plugins>=1.6.0<1.9.0
1.9.0
linuxfoundation Cni Network Plugins>=1.6.0<1.9.0

Event History

Dec 9, 2025
Advisory Published
via GitHub·05:18 PM
Data Sourced
via GitHub·05:18 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·11:13 PM
Data Sourced
via MITRE·11:13 PM
DescriptionSeverityWeakness
Dec 10, 2025
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 AM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-67499?

CVE-2025-67499 has been classified with a high severity due to its potential for exploitation in container environments.

2

How do I fix CVE-2025-67499?

To mitigate CVE-2025-67499, update the CNI `portmap` plugin to version 1.9.0 or later.

3

What systems are affected by CVE-2025-67499?

CVE-2025-67499 affects the CNI `portmap` plugin versions between 1.6.0 and 1.9.0.

4

What are the risks associated with CVE-2025-67499?

Exploitation of CVE-2025-67499 could allow unauthorized access to sensitive network communication within containerized environments.

5

Is there any workaround for CVE-2025-67499 before applying a fix?

Currently, the only recommended workaround for CVE-2025-67499 is to upgrade to a non-vulnerable version of the CNI `portmap` plugin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203