CVE-2025-1097: ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the auth-tls-match-cn Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Other sources
A security issue was discovered in ingress-nginx where the auth-tls-match-cn Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
— GitHub
Ingress Controllers play a critical role within Kubernetes clusters by enabling the functionality of Ingress resources. Azure Kubernetes Service (AKS) is aware of several security vulnerabilities affecting the Kubernetes ingress-nginx controller, including CVE-2025-1098, CVE-2025-1974, CVE-2025-1097, CVE-2025-24514, and CVE-2025-24513. Customers running this controller on their AKS clusters are advised to update to the latest patched versions (v1.11.5 and v1.12.1) to mitigate potential risks.
— Microsoft
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1097?
CVE-2025-1097 is considered a high severity vulnerability that can potentially allow remote code execution.
How do I fix CVE-2025-1097?
To mitigate CVE-2025-1097, upgrade your ingress-nginx controller to the latest versions where the vulnerability is patched.
What are the potential impacts of CVE-2025-1097?
CVE-2025-1097 can lead to unauthorized access and control over the Kubernetes environment, impacting application security.
Which software is affected by CVE-2025-1097?
CVE-2025-1097 affects the Kubernetes ingress-nginx controller within Azure Kubernetes Service.
How can organizations detect CVE-2025-1097?
Organizations can detect CVE-2025-1097 by performing vulnerability assessments and reviewing the versions of their ingress-nginx controllers.