CVE-2025-24514: ingress-nginx controller - configuration injection via unsanitized auth-url annotation
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the auth-url Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Other sources
A security issue was discovered in ingress-nginx where the auth-url Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
— GitHub
Ingress Controllers play a critical role within Kubernetes clusters by enabling the functionality of Ingress resources. Azure Kubernetes Service (AKS) is aware of several security vulnerabilities affecting the Kubernetes ingress-nginx controller, including CVE-2025-1098, CVE-2025-1974, CVE-2025-1097, CVE-2025-24514, and CVE-2025-24513. Customers running this controller on their AKS clusters are advised to update to the latest patched versions (v1.11.5 and v1.12.1) to mitigate potential risks.
— Microsoft
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-24514?
CVE-2025-24514 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-24514?
To mitigate CVE-2025-24514, update the ingress-nginx controller to the latest version that patches this vulnerability.
What systems are affected by CVE-2025-24514?
CVE-2025-24514 affects the Azure Kubernetes Service, particularly those using the ingress-nginx controller.
What type of vulnerability is CVE-2025-24514?
CVE-2025-24514 is categorized as a remote code execution vulnerability within Kubernetes.
What are the potential impacts of CVE-2025-24514?
The potential impacts of CVE-2025-24514 include unauthorized access and control over the Kubernetes environment, leading to data breaches.