PT-2026-6670 · Kubernetes+1 · Ingress-Nginx+1
Jan-Otto Kröpke
·
Published
2026-02-06
·
Updated
2026-03-10
·
CVE-2025-15566
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ingress-nginx (affected versions not specified)
Description
A security issue exists in ingress-nginx where the
nginx.ingress.kubernetes.io/auth-proxy-set-headers Ingress annotation can be used to inject configuration into nginx. This can result in arbitrary code execution within the context of the ingress-nginx controller and potential disclosure of Secrets accessible to the controller. In a default installation, the controller has access to all Secrets cluster-wide. The annotation https://t.co/5vaSyCfUF2 is also implicated in this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Ingress-Nginx