“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control
ID: b8636f84-b9a4-5b9f-abc2-08dd910a6314
STIX ID: report--b8636f84-b9a4-5b9f-abc2-08dd910a6314
Feed Name: cybersecurityNews.com
**IngressNightmare** is an advisory detailing four critical vulnerabilities in the Ingress NGINX Controller that permit annotation-based configuration injection and, in the worst case, unauthenticated remote code execution (notably CVE-2025-1974, CVSS 9.8); the report describes affected versions, the attack flow (scanning for exposed controllers, submitting malicious Ingress objects to an unauthenticated admission webhook, and triggering nginx -t to execute injected directives), the potential for full cluster takeover and secret exfiltration, and recommended mitigations such as upgrading to v1.11.5/v1.12.1 or restricting/disabling the admission webhook.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
