IngressNightmare: Kubernaughty Kubernetes
ID: 1ad9133a-b21e-5c1c-addc-d74899d2932f
STIX ID: report--1ad9133a-b21e-5c1c-addc-d74899d2932f
Feed Name: Censys Blog
Date Published: 2025-03-25
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
The Censys Research Team details a remote code execution vulnerability in the Kubernetes NGINX Ingress Controller where crafted AdmissionReview requests can be turned into malicious NGINX configurations if the controller's validation endpoint is exposed externally; Censys found certificate fingerprints and search queries suggesting ~5,000 hosts exhibiting the characteristic TLS certs, and the ingress-nginx project has released fixes (v1.12.1 and v1.11.5).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
