Skip to content
This repository was archived by the owner on Mar 24, 2026. It is now read-only.

Moderate severity CVE-2025-23419 flagged #14181

@sammedsingalkar09

Description

@sammedsingalkar09

Version
ingress-nginx v1.14.0, .....

Scanner
https://nvd.nist.gov/vuln/detail/CVE-2025-23419
GHSA-84xh-pwc6-7g4g

Test With
Version scanned: ingress-nginx v1.14.0 (latest)

Description
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets

Remediation:
Apply the latest patches and updates provided by the respective vendors.
Bump NGINX version to 1.27.4 (current 1.27.1)

Metadata

Metadata

Assignees

Labels

kind/bugCategorizes issue or PR as related to a bug.needs-priorityneeds-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions