S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 10, 2025

CVE-2025-1097 Scanner

CVE-2025-1097 Scanner - Code Injection vulnerability in Ingress-Nginx Controller

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-1097
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
ingress-nginxby kubernetes
0
Updated Aug 22, 2026View on NVD →
Detail

The Ingress-Nginx Controller is widely used in Kubernetes environments to manage and route external traffic to services running inside the cluster. It acts as an entry point for applications deployed in the Kubernetes, handling tasks such as load balancing, SSL termination, and name-based virtual hosting. Operators and developers use the Ingress-Nginx Controller to ensure scalable and secure application delivery. By facilitating refined traffic management policies, it helps maintain high availability and resilience of applications. This controller is integral to many cloud-native architectures, supporting environments ranging from small-scale to enterprise-level setups.

The detected vulnerability involves a configuration injection through the unsanitized `auth-tls-match-cn` annotation. An attacker could exploit this weakness to manipulate the configuration of the Ingress-Nginx Controller. Successful exploitation might lead to arbitrary code execution, allowing attackers to compromise systems significantly. The vulnerability allows managing critical server components unsafely, potentially exposing authentication secrets. It represents a substantial security risk, necessitating immediate attention and mitigation strategies.

This vulnerability primarily resides in the `auth-tls-match-cn` annotation, which lacks proper sanitization mechanisms. Exploiting this vulnerability involves injecting configuration directives into the Nginx configuration, potentially allowing the execution of arbitrary commands. The vulnerability facilitates unauthorized manipulation of server configurations via crafted annotations leading to command injection. Attackers gain the capability to alter service behavior or access sensitive information by exploiting this flaw. The impact severity is high given that it can be leveraged for remote code execution within controlled environments.

If exploited, the code injection vulnerability may have several severe consequences. There is a risk of unauthorized code execution, leading to potential takeover or interruption of services. Sensitive data, such as cluster-wide secrets accessible to the controller, might be exposed to malicious entities. Altered configurations can disrupt service availability, negatively impacting business operations and user experience. Organizations could face significant security compromises if not addressed, potentially allowing attackers to execute commands and conduct further attacks within the network. Ensuring systems are updated and patched is crucial to prevent exploitation.

REFERENCES

Solution Advice
  • Update the Ingress-Nginx Controller to the latest patched version provided by the maintainers.
  • Apply strict validation and sanitization of all configuration annotations to prevent injection flaws.
  • Regularly audit Kubernetes and Nginx configurations for unexpected changes or vulnerabilities.
  • Monitor network traffic for unusual activity that may suggest exploitation attempts.
  • Implement defense-in-depth strategies, such as Web Application Firewalls (WAF), to mitigate potential attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.