CVE-2025-24514 is a critical configuration injection vulnerability in ingress-nginx, allowing arbitrary code execution and Secret disclosure within Kubernetes clusters. This high-severity flaw (CVSS 8.8) is easily exploitable remotely with low privileges, enabling attackers to compromise the ingress-nginx controller and potentially the entire cluster. While not yet on the CISA KEV catalog, exploit code is publicly available (Metasploit, Nuclei, ExploitDB), and it has garnered significant community discussion and media attention, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.11.4CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
Mar 25, 2025ingress-nginx: ingress-nginx controller - configuration injection via unsanitized auth-url annotation
Mar 24, 2025Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
Mar 11, 2025ingress-nginx controller configuration injection via unsanitized auth-url annotation
ingress-nginx controller configuration injection via unsanitized auth-url annotation
ingress-nginx controller configuration injection via unsanitized auth-url annotation
ingress-nginx controller configuration injection via unsanitized auth-url annotation