CVE-2026-25804
Antrea has invalid enforcement order for network policy rules caused by integer overflow in antrea.io/antrea.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: antrea.io/antrea before v2.3.2, from v2.4.0 before v2.4.3.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/antrea-io/antrea/security/advisories/GHSA-86x4-wp9f-wrr9, https://nvd.nist.gov/vuln/detail/CVE-2026-25804, https://gist.github.com/antoninbas/c429cc3e5bb8479ba7ff38fd6fde59d9, https://github.com/antrea-io/antrea/blob/main/docs/antrea-network-policy.md, https://github.com/antrea-io/antrea/commit/86c4b6010f3be536866f339b632621c23d7186fa, https://github.com/antrea-io/antrea/pull/7496
