Securitykubernetes_cveAlphaLab AI score 26/100
CVE-2025-15566: Configuration Injection Flaw in ingress-nginx auth-proxy-set-headers
A vulnerability identified as CVE-2025-15566 has been disclosed in the ingress-nginx component's auth-proxy-set-headers feature, allowing for nginx configuration injection. This issue arises when improperly sanitized user input is processed by the feature, potentially enabling attackers to modify nginx configurations and disrupt service operations. The vulnerability underscores the importance of rigorous input validation in Kubernetes ingress controllers. Organizations using ingress-nginx are advised to review their configurations and apply patches promptly upon release.