CVE-2025-1097 is a critical configuration injection vulnerability in ingress-nginx, specifically affecting the auth-tls-match-cn Ingress annotation. This flaw allows authenticated attackers to inject arbitrary configuration into nginx, potentially leading to remote code execution within the ingress-nginx controller and disclosure of sensitive Secrets. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 98/100, this vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not yet in the CISA KEV catalog, public exploit code exists, including a Metasploit module and Nuclei templates, and it has garnered substantial community discussion and media coverage, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.11.4CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
Mar 25, 2025ingress-nginx: ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
Mar 24, 2025Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
Mar 11, 2025ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation
ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation
ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation
ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation