logo

The 'IngressNightmare' vulnerabilities in the Kubernetes Ingress NGINX Controller: Overview, detection, and remediation

ID: ea1117bc-4164-5d73-b7b2-65aa99d937de

STIX ID: report--ea1117bc-4164-5d73-b7b2-65aa99d937de

Feed Name: Datadog Security Labs

Threat Score
85/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

...
...

**IngressNightmare (CVE-2025-1974) executive summary:** Researchers disclosed five vulnerabilities in the ingress-nginx controller for Kubernetes, notably CVE-2025-1974, a critical (CVSS 9.8) unauthenticated RCE in the admission webhook that, if the webhook is reachable (externally or from any pod), can be chained to achieve code execution and full cluster privilege escalation; the report lists affected versions, detection indicators (log strings and audit events), proof-of-concept reproduction steps, and remediation guidance (upgrade to v1.12.1+/v1.11.5+ or restrict webhook network access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.