Significant Ingress NGINX Controller Flaw Enables Remote Code Execution Without Authorization
An array of five significant security deficiencies have been revealed in the Ingress NGINX Controller for Kubernetes that may lead to unauthorized remote code execution, endangering more than 6,500 clusters by exposing the module to the public web.
These vulnerabilities (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974), have been given a CVSS rating of
These vulnerabilities (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, and CVE-2025-1974), have been given a CVSS rating of
