PoC Index

CVE-2025-1097

HIGH 8.8EPSS 35.5%

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
35.53% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high · CWE-20
Published
2025-03-24
Updated
2026-02-26

Proof-of-concept exploits (6)

Nuclei templates (1)

ExploitDB entries (1)

References

Related