Kong Ingress Controller is not affected by IngressNightmare

Uses: Kong Gateway
TL;DR

Is Kong Ingress Controller affected by the IngressNightmare vulnerability?

No. IngressNightmare (CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974) affects Ingress-nginx configurations that construct file paths, which KIC does not do, so KIC is not impacted.

Problem

Kong Ingress Controller users need to know whether they are affected by the vulnerability codenamed “IngressNightmare”.

Solution

Kong Ingress Controller (KIC) is not impacted or affected by the vulnerability “IngressNightmare”.

In Ingress-nginx, some configurations rely on constructing file paths, but KIC does not. As a result, KIC remains unaffected by this vulnerability.

Vulnerabilities included in IngressNightmare:

CVE-2025-24513

CVE-2025-24514

CVE-2025-1097

CVE-2025-1098

CVE-2025-1974

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!