
🚨 CVE-2025-24514 : CRITICAL KUBERNETES RCE ALERT 🚨 A critical unauthenticated remote code execution vulnerability has been disclosed in ingress-nginx, exploitable via malicious injection in the `http://nginx.ingress.kubernetes.io/auth-url` annotation. A single crafted Ingress resource can lead to full cluster compromise. Risk Severity: - Critical (CVSS 10.0, active exploitation, public proof-of-concept available, trending) Impact: - Unauthenticated remote code execution in ingress-nginx controller - Cluster-wide Secret disclosure (tokens, DB creds, TLS certs, cloud API keys) - Complete breakdown of multi-tenant isolation - Ingress traffic interception and manipulation - Lateral movement across all namespaces - Persistent backdoors at the control-plane edge Root Cause: - CWE-94 (Improper Control of Generation of Code). The ingress-nginx controller fails to properly validate and sanitize user-supplied values in the `auth-url` annotation, allowing malicious configuration directives to be injected into the generated NGINX configuration and executed during reload. Attackers can: - Inject malicious directives via a crafted Ingress annotation - Trigger NGINX config reloads leading to command execution - Gain RCE inside the privileged controller pod - Enumerate and exfiltrate Secrets across all namespaces - Intercept, modify, or reroute all ingress traffic - Establish persistence by backdooring ingress routes or controller configs Are You Affected? - Vulnerable: Ingress-nginx deployments with the current auth-url annotation parser - Scope: Multi-tenant clusters, CI/CD environments, managed Kubernetes services, and any cluster where users can create or modify Ingress resources Immediate Action Required: - Update: Monitor the ingress-nginx GitHub repository and upgrade immediately once the emergency patch is released - Mitigation: Restrict Ingress creation via RBAC, block `http://nginx.ingress.kubernetes.io/auth-url` annotations using OPA Gatekeeper or Kyverno, and isolate controller pods with strict network policies - Audit: Hunt for auth-url annotations across all namespaces, monitor controller logs for abnormal reloads, and alert on unexpected outbound traffic from ingress-nginx pods Ingress controllers sit at the blast radius edge of every cluster. Treat this as a cluster-wide incident, not a namespace issue. 🛡️ #ostorlabCVE
Post summary
CVE-2025-24514 is a critical unauthenticated RCE in ingress‑nginx via the auth‑url annotation, with active exploitation reported, a public PoC available, and urgent patch/mitigation steps advised.

