CVE-2025-1098 is a critical security vulnerability in ingress-nginx, where specially crafted `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This flaw can lead to arbitrary code execution within the ingress-nginx controller and disclosure of sensitive Secrets, which by default can include all cluster-wide Secrets. The vulnerability has a CVSS score of 8.8 (HIGH), indicating a severe risk with a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Its EPSS score is exceptionally high, suggesting a significant likelihood of exploitation. While not yet confirmed as actively exploited in the wild (KEV: No), exploit intelligence indicates the availability of Nuclei templates and an ExploitDB entry (EDB-52475) detailing an FD Injection to RCE. The vulnerability has garnered substantial community discussion and media coverage, highlighting its critical nature and potential for widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.11.4CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ingress-nginx controller - configuration injection via unsanitized mirror annotations
Mar 25, 2025ingress-nginx: ingress-nginx controller - configuration injection via unsanitized mirror annotations
Mar 24, 2025Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
Mar 11, 2025ingress-nginx controller configuration injection via unsanitized mirror annotations
ingress-nginx controller configuration injection via unsanitized mirror annotations
ingress-nginx controller configuration injection via unsanitized mirror annotations
ingress-nginx controller configuration injection via unsanitized mirror annotations