logo

CVE-2025-1974: Critical Unauthenticated RCE Vulnerability in Ingress NGINX for Kubernetes

ID: ce442f35-1a04-53f3-9778-9ebc6a975457

STIX ID: report--ce442f35-1a04-53f3-9778-9ebc6a975457

Feed Name: Arctic Wolf

Threat Score
80/100

Date Published: 2025-03-25

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On March 24, 2025, ingress-nginx maintainers released fixes for multiple vulnerabilities, including CVE-2025-1974 — a critical unauthenticated RCE via the ingress-nginx Validating Admission Controller that can allow actors on the Pod network to inject arbitrary NGINX configuration and potentially take over Kubernetes clusters; affected versions are prior to 1.12.1 and 1.11.5 and users are advised to upgrade or disable the Validating Admission Controller as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.