logo

Security alert: IngressNightmare (NGINX controller for Kubernetes)

ID: 80ffa2a8-d601-5bc3-9f7d-5e0542de11e5

STIX ID: report--80ffa2a8-d601-5bc3-9f7d-5e0542de11e5

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

Author: Myles Satterfield

...
...

**TL;DR:** Five vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, CVE-2025-24513, CVE-2025-24514) in the Ingress NGINX Controller for Kubernetes (disclosed 2025-03-24, called IngressNightmare) can be combined to achieve remote code execution and unauthorized access to namespace secrets leading to potential cluster takeover; patches are available in controller v1.12.1 and v1.11.5 and disabling the Validating Admission Controller is recommended as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.