chiprook
← Security
SecuritySeptember 24, 2026, 18:08

Tag confusion in AWS Load Balancer Controller can expose databases to the internet

A researcher demonstrated in HackerOne #1238482 that a developer with standard EKS namespace access and ec2:CreateTags permission can tag any security group with the controller's expected tags, create a matching Ingress, and make the AWS Load Balancer Controller open port 22 to 0.0.0.0/0. The controller relies solely on tags to determine ownership, and tags are not a security boundary.

Tag confusion in AWS Load Balancer Controller can expose databases to the internet
#AWS#Kubernetes#EKS
Read next
Security

Airties adds router-level cybersecurity protection for ISPs

Security

Study Finds Instagram and Facebook Are the Most Invasive Apps

Security

CERT Polska: Meta ads funneled Polish users into premium-rate billing scam

Security

Revolut customers hit by fresh hack via US stock broker