logo

Ingress Nightmare: Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress-NGINX

ID: bce22da8-82ea-5d4e-be60-c8cc564072f3

STIX ID: report--bce22da8-82ea-5d4e-be60-c8cc564072f3

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2025-03-25

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

On March 24, 2025 a security advisory disclosed five vulnerabilities in ingress-nginx — most critically CVE-2025-1974 (CVSS 9.8) — that enable unauthenticated configuration injection, remote code execution, and potential exposure of Kubernetes Secrets across affected versions (all prior to v1.11.0, v1.11.0–v1.11.4, and v1.12.0); administrators are urged to upgrade to v1.12.1 or v1.11.5 immediately or apply temporary mitigations such as disabling the Validating Admission Controller.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.