Path traversal in NGINX Ingress Controller - CVE-2025-14727

 

Path traversal in NGINX Ingress Controller - CVE-2025-14727

Published: December 19, 2025


Vulnerability identifier: #VU120226
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14727
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges. 

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated user with ingress creation privileges can inject arbitrary NGINX configuration directives and gain access to sensitive information or escalate privileges. 


Affected software

NGINX Ingress Controller

How to mitigate CVE-2025-14727

Install updates from vendor's website.

NGINX Ingress Controller - update to 5.3.1

External References

Related Security Bulletins