CVE-2025-59303: Medium severity HAProxy Kubernetes Ingress Controller vulnerability
HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59303?
CVE-2025-59303 is considered a high-severity vulnerability due to its potential for exposing sensitive ingress token secrets.
How do I fix CVE-2025-59303?
To fix CVE-2025-59303, upgrade to HAProxy Kubernetes Ingress Controller version 3.1.13 or later.
Which versions are affected by CVE-2025-59303?
CVE-2025-59303 affects HAProxy Kubernetes Ingress Controller versions prior to 3.1.13 and specific versions of HAProxy Enterprise Kubernetes Ingress Controller.
What are the risks associated with CVE-2025-59303?
The risks associated with CVE-2025-59303 include unauthorized access to ingress token secrets which can compromise the security of the Kubernetes cluster.
Is there a workaround for CVE-2025-59303?
A temporary workaround for CVE-2025-59303 is to disable the config-snippets feature until the software can be updated.