Security alert: IngressNightmare (NGINX controller for Kubernetes)
ID: 80ffa2a8-d601-5bc3-9f7d-5e0542de11e5
STIX ID: report--80ffa2a8-d601-5bc3-9f7d-5e0542de11e5
Feed Name: Expel Blog
Threat Score
**TL;DR:** Five vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, CVE-2025-24513, CVE-2025-24514) in the Ingress NGINX Controller for Kubernetes (disclosed 2025-03-24, called IngressNightmare) can be combined to achieve remote code execution and unauthorized access to namespace secrets leading to potential cluster takeover; patches are available in controller v1.12.1 and v1.11.5 and disabling the Validating Admission Controller is recommended as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
