# Ingress-nginx-controller: Nightmare on CVE Street

DevFeed: [Ingress-nginx-controller: Nightmare on CVE Street](<https://devfeed.tech/articles/ingress-nginx-controller-nightmare-on-cve-street-13103.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ingress-nginx-controller-nightmare-on-cve-street>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [nginx](<https://devfeed.tech/topics/nginx.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wiz](<https://devfeed.tech/tags/wiz.md>)

## AI overview

The article describes several critical remote code execution vulnerabilities affecting the Ingress-nginx-controller, including risks to Kubernetes cluster secrets, service availability, privileges, and security controls. It also explains how Chainguard reviewed its infrastructure, identified affected Chainguard Containers, and prepared patches using Chainguard OS's continuous update model.

## Source excerpt

Chainguard was able to quickly respond to and handle the recent ingress-nginx-controller CVEs that were discovered by Wiz. See the actions we have taken.