PT-2026-6670 · Kubernetes+1 · Ingress-Nginx+1

Jan-Otto Kröpke

·

Published

2026-02-06

·

Updated

2026-03-10

·

CVE-2025-15566

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ingress-nginx (affected versions not specified)
Description A security issue exists in ingress-nginx where the nginx.ingress.kubernetes.io/auth-proxy-set-headers Ingress annotation can be used to inject configuration into nginx. This can result in arbitrary code execution within the context of the ingress-nginx controller and potential disclosure of Secrets accessible to the controller. In a default installation, the controller has access to all Secrets cluster-wide. The annotation https://t.co/5vaSyCfUF2 is also implicated in this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03604
BIT-NGINX-INGRESS-CONTROLLER-2025-15566
CVE-2025-15566

Affected Products

Red Os
Ingress-Nginx