CVE-2025-24513Medium· 4.8▾ Sunlitingress-nginx controller - auth secret file path traversal vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.5%
A security issue was discovered in ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.
k8s.io/ingress-nginx < 1.11.5k8s.io/ingress-nginx >= 1.12.0-beta.0, < 1.12.1Upgrade to a patched release:
k8s.io/ingress-nginx 1.11.5k8s.io/ingress-nginx 1.12.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-1097High· 8.8ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
CVE-2026-24513Low· 3.1ingress-nginx has Improper Check for Unusual or Exceptional Conditions
CVE-2026-24514Medium· 6.5ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2021-25745High· 8.1Improper Input Validation in k8s.io/ingress-nginx
CVE-2018-1002104Medium· 5.3Kubernetes ingress exposes sensitive information
CVE-2020-8553Medium· 5.9ingress-nginx component for Kubernetes allows file overwrite