CVE-2025-14727: NGINX Ingress Controller vulnerability
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
A vulnerability exists in the NGINX Ingress Controller nginx.org/rewrite-target annotation validation.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14727?
CVE-2025-14727 has been classified with a high severity due to its potential impact on the NGINX Ingress Controller.
How do I fix CVE-2025-14727?
To mitigate CVE-2025-14727, upgrade your NGINX Ingress Controller to version 5.3.1 or higher where the validation issue is resolved.
Which versions of NGINX Ingress Controller are affected by CVE-2025-14727?
CVE-2025-14727 affects NGINX Ingress Controller versions up to and including 5.3.0.
What type of vulnerability is CVE-2025-14727?
CVE-2025-14727 is a validation vulnerability related to the nginx.org/rewrite-target annotation in NGINX Ingress Controller.
Is there a workaround for CVE-2025-14727?
Currently, the recommended action for CVE-2025-14727 is to upgrade to a non-vulnerable version of the software rather than relying on a workaround.