logo

IngressNightmare: Kubernaughty Kubernetes

ID: 1ad9133a-b21e-5c1c-addc-d74899d2932f

STIX ID: report--1ad9133a-b21e-5c1c-addc-d74899d2932f

Feed Name: Censys Blog

Threat Score
72/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

The Censys Research Team details a remote code execution vulnerability in the Kubernetes NGINX Ingress Controller where crafted AdmissionReview requests can be turned into malicious NGINX configurations if the controller's validation endpoint is exposed externally; Censys found certificate fingerprints and search queries suggesting ~5,000 hosts exhibiting the characteristic TLS certs, and the ingress-nginx project has released fixes (v1.12.1 and v1.11.5).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.