F5 Security Update – 22 December 2025

F5 has released a security update to address a vulnerability affecting NGINX Ingress Controller version 5.3.0.

he addressed vulnerability could allow the attacker to perform denial of service attacks, obtain sensitive information, or gain elevated privileges on the affected product.

NGINX Ingress Controller Path Traversal Vulnerability (CVE-2025-14727):

  • CVSS: 8.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities

CVE-2025-14727

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References