AI description
CVE-2025-15566 is a vulnerability found in the Kubernetes ingress-nginx controller. It stems from improper input validation (CWE-20) concerning the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation. This annotation, intended for setting authentication proxying headers, can be manipulated due to insufficient validation. Exploiting this flaw allows an attacker to inject arbitrary configuration directives into the nginx configuration managed by the ingress controller. Given that the ingress-nginx controller typically operates with elevated privileges and often has cluster-wide access to Kubernetes Secrets, successful exploitation could lead to arbitrary code execution within the controller's context and the unauthorized disclosure of sensitive Secrets.
- Description
- A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
- Source
- jordan@liggitt.net
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- jordan@liggitt.net
- CWE-20
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
11
no this cve, CVE-2025-15566 is not from the set earlier this week - this is just the non-stop security nightmare that is kubernetes https://t.co/jIcxg8dr0D
@nanovms
6 Feb 2026
186 Impressions
2 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15566 #devopsish #kubernetes #cve https://t.co/mIyVR7HGKV
@ChrisShort
6 Feb 2026
119 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15566: ingress-nginx auth-proxy-set-headers nginx configuration injection - https://t.co/fmNcoelbFa
@kubernetesio
6 Feb 2026
5080 Impressions
7 Retweets
33 Likes
17 Bookmarks
3 Replies
0 Quotes
CVE-2025-15566: ingress-nginx auth-proxy-set-headers nginx configuration injection - https://t.co/w1VtoO3WAv
@K8sContributors
6 Feb 2026
727 Impressions
1 Retweet
11 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-15566 Kubernetes Ingress-Nginx Arbitrary Code Execution via Header Injection Annotation https://t.co/13fssoOBrk
@VulmonFeeds
6 Feb 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15566 A security issue was discovered in ingress-nginx where the `https://t.co/5vaSyCfUF2` Ingress annotation can be used to inject configuration… https://t.co/iXN8vewOdK
@CVEnew
6 Feb 2026
206 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes