NGINX Ingress Controller Vulnerability in Annotation Validation
CVE-2025-14727

8.7HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
17 December 2025

What is CVE-2025-14727?

A vulnerability has been identified in the NGINX Ingress Controller that affects the validation of the nginx.org/rewrite-target annotations. This flaw can potentially be exploited, leading to unexpected behavior or misconfiguration, which could have significant implications for application security. Users are encouraged to review the associated advisory and apply necessary updates to mitigate any risks.

Affected Version(s)

NGINX Ingress Controller 5.3.0 < 5.3.1

NGINX Ingress Controller 5.2.0

NGINX Ingress Controller 5.1.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Ricardo Katz of Red Hat for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.
CVE-2025-14727 : NGINX Ingress Controller Vulnerability in Annotation Validation