Skip to content
This repository was archived by the owner on Mar 24, 2026. It is now read-only.

Controller image CVE-2025-15467 from openssl #14482

@rparini-intellegens

Description

@rparini-intellegens

Reported in Google Cloud's Security command center and Docker scout v1.19.0. To reproduce:

docker scout cves registry.k8s.io/ingress-nginx/controller:v1.14.2

The ingress-nginx/controller:v1.14.2 image contains openssl version 3.5.4-r0 which has recently disclosed several CVEs but the most notable is the Critical CVE-2025-15467 which can potentially allow for Remote Code Execution.

Is the ingress-nginx controller potentially vulnerable to this through its use of openssl? If so, is there some configuration of the controller that would mitigate the issue?

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.needs-priorityneeds-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions