icon

We found results for “

CVE-2025-59303

Good to know:

icon

Date: October 7, 2025

HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1.

Severity Score

Severity Score

Weakness Type (CWE)

Incomplete Filtering of Special Elements

CWE-791

Top Fix

icon

Upgrade Version

Upgrade to version github.com/haproxytech/kubernetes-ingress - v3.2.0;https://github.com/haproxytech/kubernetes-ingress.git - v3.2.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us