AWS Latest Bulletins
Follow
Issues with Kubernetes ingress-nginx controller (Multiple CVEs)
AWS is aware of several vulnerabilities affecting the Kubernetes ingress-nginx controller, including CVE-2025-1098, CVE-2025-1974, CVE-2025-1097, CVE-2025-24514, and CVE-2025-24513. Amazon Elastic Kubernetes Service is not affected by these issues as it does not provide or install the ingress-nginx controller. However, customers who have installed this controller on their clusters are advised to update to the latest version to address the vulnerabilities. Customers with security questions or concerns can email [email protected] for assistance.