F5-K000158176: High severity F5 NGINX Ingress Controller vulnerability
Published Dec 17, 2025
·Updated
A vulnerability exists in the NGINX Ingress Controller nginx.org/rewrite-target annotation validation.
Affected Software
2 affected componentsFixes available
F5 NGINX Ingress Controller=5.3.0
5.3.1
F5 NGINX Ingress Controller
Event History
Dec 17, 2025
Advisory Published
via F5·02:56 PM
Data Sourced
via F5·02:56 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000158176?
F5-K000158176 is classified as a moderate severity vulnerability.
2
How do I fix F5-K000158176?
To fix F5-K000158176, ensure that the NGINX Ingress Controller is updated to version 5.3.1 or later.
3
What is the impact of F5-K000158176?
The impact of F5-K000158176 allows potential validation issues with the nginx.org/rewrite-target annotation in the NGINX Ingress Controller.
4
Which versions of NGINX Ingress Controller are affected by F5-K000158176?
F5-K000158176 affects versions 5.3.0 and earlier of the F5 NGINX Ingress Controller.
5
Is there a workaround for F5-K000158176?
While updating is the recommended solution, disabling the nginx.org/rewrite-target annotation can serve as a temporary workaround.