logo

IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX

ID: 2629c38d-c11f-5cec-89ad-e99e811c7dd3

STIX ID: report--2629c38d-c11f-5cec-89ad-e99e811c7dd3

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

**IngressNightmare (Wiz Research)**: Wiz Research disclosed a critical chain of vulnerabilities in the Ingress NGINX Controller (multiple CVEs, CVSS 9.8) that allow unauthenticated injection of NGINX configuration via AdmissionReview inputs and ingresses, enabling remote code execution by loading an uploaded shared library and leading to full cluster secret access and potential cluster takeover; the report provides technical details, affected versions, mitigations (upgrade to 1.12.1/1.11.5, restrict admission webhook network access, or disable it temporarily), detection guidance, and responsible disclosure timeline, and highlights wide real-world exposure and migration/EOL guidance for ingress-nginx.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.