Detecting and Mitigating IngressNightmare – CVE-2025-1974
ID: f6eec4be-49c8-51e4-8597-55fe99f660ff
STIX ID: report--f6eec4be-49c8-51e4-8597-55fe99f660ff
Feed Name: Sysdig Blog
A set of critical vulnerabilities affecting the Ingress NGINX Controller for Kubernetes (notably CVE-2025-1974, CVSS 9.8) were disclosed; the most severe enables unauthenticated remote code execution via uploading a shared library and forcing NGINX to load it through an admission webhook. The report details exploitation steps, provides a Falco detection rule and Sysdig Secure policy, lists affected versions (< v1.11.0, v1.11.0–1.11.4, v1.12.0) and fixed releases (v1.11.5, v1.12.1), and recommends immediate patching and ensuring the admission webhook is not publicly exposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
