logo

“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control

ID: b8636f84-b9a4-5b9f-abc2-08dd910a6314

STIX ID: report--b8636f84-b9a4-5b9f-abc2-08dd910a6314

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-04-05

Date Updated: 2026-04-21

Author: Balaji N

...
...

**IngressNightmare** is an advisory detailing four critical vulnerabilities in the Ingress NGINX Controller that permit annotation-based configuration injection and, in the worst case, unauthenticated remote code execution (notably CVE-2025-1974, CVSS 9.8); the report describes affected versions, the attack flow (scanning for exposed controllers, submitting malicious Ingress objects to an unauthenticated admission webhook, and triggering nginx -t to execute injected directives), the potential for full cluster takeover and secret exfiltration, and recommended mitigations such as upgrading to v1.11.5/v1.12.1 or restricting/disabling the admission webhook.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.