CVE-2025-59303Medium· 6.4▾ SunlitHAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. Th…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14731Medium· 6.3A weakness has been identified in CTCMS Content Management System up to 2.1.2
CVE-2026-47323Critical· 9.8Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
CVE-2026-103540Medium· 6.3A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1
CVE-2026-102771Medium· 4.7A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7
CVE-2026-81521Medium· 6.5The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation
CVE-2026-92018Critical· 9.6Sandbox escape in the DOM: Core & HTML component