logo

CVE-2025-1974

ID: 08b4c691-a46c-5e73-8e39-f0e7742c2f0b

STIX ID: report--08b4c691-a46c-5e73-8e39-f0e7742c2f0b

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

...
...

Ingress-nginx maintainers released fixes for multiple vulnerabilities on March 24, 2025, including a critical CVE-2025-1974 that allows unauthenticated attackers on the Pod network to inject arbitrary NGINX configuration and achieve remote code execution via the Validating Admission Controller; users should upgrade to fixed versions (1.12.1 / 1.11.5) or disable the admission controller as a temporary workaround and verify deployments with kubectl.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.